Plugin Vulnerability Hub
Plugin 38 known issues Latest disclosed Apr 07, 2026

Element Pack – Widgets, Templates & Addons for Elementor Vulnerabilities

Review known vulnerability records for the WordPress plugin Element Pack – Widgets, Templates & Addons for Elementor (`bdthemes-element-pack-lite`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-4655, CVE-2026-40745 and CVE-2026-1793, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
38
High or Critical
1
Patch Coverage
100%
Last Updated
May 07, 2026
Related Security Guides

Use these guides while reviewing Element Pack – Widgets, Templates & Addons for Elementor fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Element Pack – Widgets, Templates & Addons for Elementor remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
38
1. Match the Package
Confirm the installed WordPress plugin slug is bdthemes-element-pack-lite before acting on any CVE from this cluster.
2. Sort by Severity
Start with 1 high or critical record, then review medium and unrated findings with public references.
3. Check Patch Evidence
38 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Element Pack – Widgets, Templates & Addons for Elementor CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
38
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2024-30496
Element Pack Elementor Addons <= 5.5.3 - Authenticated (Contributor+) SQL Injection
SQL Injection Versions up to 5.5.3 5.5.4 CVSS 9.9
CVE-2026-1793
Element Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary...
Vulnerability Versions up to 8.3.17 8.3.18 CVSS 6.5
CVE-2024-9657
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carou...
Stored Cross-Site Scripting Versions up to 5.10.2 5.10.3 CVSS 6.5
CVE-2024-4359
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carou...
Vulnerability Versions up to 5.7.2 5.7.3 CVSS 6.5
CVE-2026-4655
Element Pack Addons for Elementor <= 8.4.2 - Authenticated (Contributor+) Stored Cro...
Stored Cross-Site Scripting Versions up to 8.4.2 8.5.0 CVSS 6.4
CVE-2025-5944
Element Pack Addons for Elementor <= 8.0.0 - Authenticated (Contributor+) DOM-Based...
Stored Cross-Site Scripting 8.0.0 through 8.0.0 8.1.0 CVSS 6.4
CVE-2025-5292
Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Bloc...
Stored Cross-Site Scripting Versions up to 5.11.2 5.11.3 CVSS 6.4
CVE-2025-1458
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carous...
Stored Cross-Site Scripting Versions up to 5.10.29 5.10.30 CVSS 6.4
CVE-2024-30496 Critical 5.5.4
CVE-2024-30496 Element Pack – Widgets, Templates & Addons for Elementor SQL Injection

Element Pack Elementor Addons <= 5.5.3 - Authenticated (Contributor+) SQL Injection

CVE-2026-1793 Medium 8.3.18
CVE-2026-1793 Element Pack – Widgets, Templates & Addons for Elementor Vulnerability

Element Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary File Read

CVE-2024-9657 Medium 5.10.3
CVE-2024-9657 Element Pack – Widgets, Templates & Addons for Elementor Stored Cross-Site Scripting

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

CVE-2024-4359 Medium 5.7.3
CVE-2024-4359 Element Pack – Widgets, Templates & Addons for Elementor Vulnerability

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 - Authenticated (Contributor+) Arbitrary File Read

CVE-2026-4655 Medium 8.5.0
CVE-2026-4655 Element Pack – Widgets, Templates & Addons for Elementor Stored Cross-Site Scripting

Element Pack Addons for Elementor <= 8.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Image Widget

CVE-2025-5944 Medium 8.1.0
CVE-2025-5944 Element Pack – Widgets, Templates & Addons for Elementor Stored Cross-Site Scripting

Element Pack Addons for Elementor <= 8.0.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute

CVE-2025-5292 Medium 5.11.3
CVE-2025-5292 Element Pack – Widgets, Templates & Addons for Elementor Stored Cross-Site Scripting

Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

CVE-2025-1458 Medium 5.10.30
CVE-2025-1458 Element Pack – Widgets, Templates & Addons for Elementor Stored Cross-Site Scripting

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.29 - Authenticated (Contributor+) Stored Cross-Site Scripting

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Element Pack – Widgets, Templates & Addons for Elementor so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
38 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 0 high severity findings.
Recent CVEs
CVE-2026-4655, CVE-2026-40745 and CVE-2026-1793
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Element Pack – Widgets, Templates & Addons for Elementor

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-4655
CVE-2026-4655: Element Pack Addons for Elementor <= 8.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Image Widget

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Image Widget in versions up to and including 8.4.2. This is due to insufficient input sanitization and output escaping on SVG content fetched from remote URLs in th...

Published
Apr 07, 2026
Patched Release
8.5.0
Affected Versions
Versions up to 8.4.2
Next Step
Update to 8.5.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-40745
CVE-2026-40745: Element Pack Elementor Addons <= 8.4.2 - Authenticated (Editor+) SQL Injection

The Element Pack Elementor Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authe...

Published
Mar 23, 2026
Patched Release
8.5.0
Affected Versions
Versions up to 8.4.2
Next Step
Update to 8.5.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-1793
CVE-2026-1793: Element Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary File Read

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the SVG widget and a lack of sufficient file validation in the 'render_svg' function. This makes it possible for authenticated attacke...

Published
Feb 14, 2026
Patched Release
8.3.18
Affected Versions
Versions up to 8.3.17
Next Step
Update to 8.3.18 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-31413
CVE-2025-31413: Element Pack Elementor Addons <= 8.3.13 - Cross-Site Request Forgery

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.13. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform...

Published
Jan 16, 2026
Patched Release
8.3.14
Affected Versions
Versions up to 8.3.13
Next Step
Update to 8.3.14 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13196
CVE-2025-13196: Element Pack Addons for Elementor <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map widget

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Street Map widget's marker content parameter in all versions up to, and including, 8.3.4. This is due to insufficient input sanitization and output escaping on use...

Published
Nov 17, 2025
Patched Release
8.3.5
Affected Versions
Versions up to 8.3.4
Next Step
Update to 8.3.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-11536
CVE-2025-11536: Element Pack Addons for Elementor <= 8.2.5 - Authenticated (Subscriber+) Blind Server-Side Request Forgery

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8.2.5 via the wp_ajax_import_elementor_template action. This makes it possible for authenticated attackers, with Subscriber-level ac...

Published
Oct 20, 2025
Patched Release
8.2.6
Affected Versions
Versions up to 8.2.5
Next Step
Update to 8.2.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-8100
CVE-2025-8100: Element Pack Elementor Addons and Templates <= 8.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content

The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content' parameter in versions up to, and including, 8.1.5 due to insufficient input sanitization and output escaping. This makes it possible for auth...

Published
Aug 05, 2025
Patched Release
8.1.6
Affected Versions
Versions up to 8.1.5
Next Step
Update to 8.1.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-5944
CVE-2025-5944: Element Pack Addons for Elementor <= 8.0.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-caption’ attribute in all versions up to, and including, 8.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticate...

Published
Jul 02, 2025
Patched Release
8.1.0
Affected Versions
8.0.0 through 8.0.0
Next Step
Update to 8.1.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-5292
CVE-2025-5292: Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content’ parameter in all versions up to, and including, 5.11.2 due to ins...

Published
May 30, 2025
Patched Release
5.11.3
Affected Versions
Versions up to 5.11.2
Next Step
Update to 5.11.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-1458
CVE-2025-1458: Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.29 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like Dual Button, Creative Button, Image Stack and more in all versions up to, and including, 5.10....

Published
Apr 25, 2025
Patched Release
5.10.30
Affected Versions
Versions up to 5.10.29
Next Step
Update to 5.10.30 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-1457
CVE-2025-1457: Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.28 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Wrapper Link, Countdown and Gallery widgets in all versions up to, and including, 5.10.28 due to insufficient i...

Published
Apr 18, 2025
Patched Release
5.10.29
Affected Versions
Versions up to 5.10.28
Next Step
Update to 5.10.29 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-12851
CVE-2024-12851: Element Pack Lite - Addons for Elementor <= 5.10.14 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes parameter of the Cookie Consent Widget in all versions up to, and including, 5...

Published
Jan 07, 2025
Patched Release
5.10.15
Affected Versions
Versions up to 5.10.14
Next Step
Update to 5.10.15 or newer if supported.