CVE-2026-92991
Deferred
Deferred - Pending Action
BaseFortify
Vulnerability report for CVE-2026-92991, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-18
Last updated on: 2026-09-18
Assigner: Wordfence
Description
Description
The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for attackers who can compromise the Sigmative API server to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| bdthemes | Live | Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator 0 |
| bdthemes | Pixel | Gallery Addons for Elementor 0 |
| bdthemes | Smart | Admin Assistant 0 |
| bdthemes | Ultimate | Store Kit – Store Builder Addons for Elementor, WooCommerce Store Builder, EDD Store Builder 0 |
| bdthemes | Ultimate | Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets 0 |
| bdthemes | Prime | Slider – Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons 0 |
| bdthemes | Element | Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |