5.4

CVE-2026-92991

Biggopti Library (Various Versions) - Cross-Site Scripting via display_id from Sigmative API

Biggopti Library (Various Versions) - Cross-Site Scripting via display_id from Sigmative API

The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for attackers who can compromise the Sigmative API server to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Mögliche Gegenmaßnahme
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons: Update to version 8.7.15, or a newer patched version
Prime Slider – Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons: Update to version 4.4.6, or a newer patched version
Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator: Update to version 1.5.9, or a newer patched version
Pixel Gallery: Update to version 2.1.15, or a newer patched version
Smart Admin Assistant: Update to version 2.2.1, or a newer patched version
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets: Update to version 4.2.1, or a newer patched version
Ultimate Store Kit – Store Builder Addons for Elementor, WooCommerce Store Builder, EDD Store Builder: Update to version 3.0.8, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerbdthemes
≫
Produkt Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator
Default Statusunaffected
Version <= 1.5.6
Version 0
Status affected
Herstellerbdthemes
≫
Produkt Pixel Gallery Addons for Elementor
Default Statusunaffected
Version <= 2.1.14
Version 0
Status affected
Herstellerbdthemes
≫
Produkt Smart Admin Assistant
Default Statusunaffected
Version <= 2.2.0
Version 0
Status affected
Herstellerbdthemes
≫
Produkt Ultimate Store Kit – Store Builder Addons for Elementor, WooCommerce Store Builder, EDD Store Builder
Default Statusunaffected
Version <= 3.0.7
Version 0
Status affected
Herstellerbdthemes
≫
Produkt Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets
Default Statusunaffected
Version <= 4.2.0
Version 0
Status affected
Herstellerbdthemes
≫
Produkt Prime Slider – Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons
Default Statusunaffected
Version <= 4.4.5
Version 0
Status affected
Herstellerbdthemes
≫
Produkt Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons
Default Statusunaffected
Version <= 8.7.14
Version 0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons
Version *-8.7.14
SystemWordPress Plugin
≫
Produkt Prime Slider – Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons
Version *-4.4.5
SystemWordPress Plugin
≫
Produkt Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator
Version *-1.5.6
SystemWordPress Plugin
≫
Produkt Pixel Gallery
Version *-2.1.14
SystemWordPress Plugin
≫
Produkt Smart Admin Assistant
Version *-2.2.0
SystemWordPress Plugin
≫
Produkt Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets
Version *-4.2.0
SystemWordPress Plugin
≫
Produkt Ultimate Store Kit – Store Builder Addons for Elementor, WooCommerce Store Builder, EDD Store Builder
Version *-3.0.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.216
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 5.4 2.2 2.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://www.wordfence.com/threat-intel/vulnerabilities/id/7bf1d6f9-afe2-41c2-968b-20dbc474cd73?source=cve
https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/tags/8.7.14/admin/assets/js/ep-admin-api-biggopti.min.js
https://plugins.trac.wordpress.org/browser/ultimate-post-kit/tags/4.2.0/admin/assets/js/upk-admin-api-biggopti.min.js
https://plugins.trac.wordpress.org/browser/live-copy-paste/tags/1.5.4/includes/promotion/biggopti/script.js
https://plugins.trac.wordpress.org/browser/pixel-gallery/tags/2.1.14/admin/assets/js/pg-admin-api-biggopti.min.js
https://plugins.trac.wordpress.org/browser/ultimate-store-kit/tags/3.0.7/assets/admin/others/js/admin-api-biggopti.js
https://plugins.trac.wordpress.org/browser/bdthemes-prime-slider-lite/tags/4.4.5/admin/assets/js/ps-admin-api-biggopti.js
https://plugins.trac.wordpress.org/browser/smart-admin-assistant/tags/2.2.0/includes/Admin/assets/js/biggopti.js
https://plugins.trac.wordpress.org/changeset/3652687/live-copy-paste
https://plugins.trac.wordpress.org/changeset/3639087/smart-admin-assistant
https://plugins.trac.wordpress.org/changeset/3638677/pixel-gallery#file564
https://plugins.trac.wordpress.org/changeset/3638663/ultimate-store-kit#file505
https://plugins.trac.wordpress.org/changeset/3638660/ultimate-post-kit#file531
https://plugins.trac.wordpress.org/changeset/3638625/bdthemes-prime-slider-lite#file428
https://plugins.trac.wordpress.org/changeset/3638640/bdthemes-element-pack-lite#file1151
https://www.wordfence.com/threat-intel/vulnerabilities/id/7bf1d6f9-afe2-41c2-968b-20dbc474cd73
Third Party Advisory