🔐 CVE Alert

CVE-2026-92991

MEDIUM 5.4

Biggopti Library (Various Versions) - Cross-Site Scripting via display_id from Sigmative API

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for attackers who can compromise the Sigmative API server to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CWE CWE-79
Vendor bdthemes
Product live copy paste for elementor – cross domain copy paste & page duplicator
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for bdthemes live copy paste for elementor – cross domain copy paste & page duplicator

Be the first to know when new medium vulnerabilities affecting bdthemes live copy paste for elementor – cross domain copy paste & page duplicator are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

bdthemes / Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator
0 ≤ 1.5.6
bdthemes / Pixel Gallery Addons for Elementor
0 ≤ 2.1.14
bdthemes / Smart Admin Assistant
0 ≤ 2.2.0
bdthemes / Ultimate Store Kit – Store Builder Addons for Elementor, WooCommerce Store Builder, EDD Store Builder
0 ≤ 3.0.7
bdthemes / Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets
0 ≤ 4.2.0
bdthemes / Prime Slider – Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons
0 ≤ 4.4.5
bdthemes / Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons
0 ≤ 8.7.14

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/7bf1d6f9-afe2-41c2-968b-20dbc474cd73?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/tags/8.7.14/admin/assets/js/ep-admin-api-biggopti.min.js plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-post-kit/tags/4.2.0/admin/assets/js/upk-admin-api-biggopti.min.js plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/live-copy-paste/tags/1.5.4/includes/promotion/biggopti/script.js plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/pixel-gallery/tags/2.1.14/admin/assets/js/pg-admin-api-biggopti.min.js plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/ultimate-store-kit/tags/3.0.7/assets/admin/others/js/admin-api-biggopti.js plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/bdthemes-prime-slider-lite/tags/4.4.5/admin/assets/js/ps-admin-api-biggopti.js plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/smart-admin-assistant/tags/2.2.0/includes/Admin/assets/js/biggopti.js plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3652687/live-copy-paste plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3639087/smart-admin-assistant plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3638677/pixel-gallery#file564 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3638663/ultimate-store-kit#file505 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3638660/ultimate-post-kit#file531 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3638625/bdthemes-prime-slider-lite#file428 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3638640/bdthemes-element-pack-lite#file1151