Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons has 42 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 42 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 9.9 out of 10. Severity breakdown: 1 critical and 0 high. 2024 was the busiest year with 26 disclosures.

The most common weakness is Cross-Site Scripting, behind 30 of the records (71%). Other recurring categories include Missing Authorization, SQL Injection.

Every one of the 42 issues recorded for Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons has a vendor fix available, so running the current release closes all known holes.

20 independent researchers contributed these findings, most of them (8) reported by Webbernaut. Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891019.09.2019Today02.02.20244.3Element Pack Elementor Addons <= 5.4.11 - Missing Authorization via bdt_duplicate_as_draft CVSS 4.3 · 02.02.202425.03.20246.4Element Pack Elementor Addons <= 5.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via link CVSS 6.4 · 25.03.202428.03.20249.9Element Pack Elementor Addons <= 5.5.3 - Authenticated (Contributor+) SQL Injection CVSS 9.9 · 28.03.202405.04.20246.4Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget CVSS 6.4 · 05.04.20246.4Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget CVSS 6.4 · 05.04.202410.04.20245.3Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.5.6 - Sensitive Information Exposure via element_pack_ajax_search CVSS 5.3 · 10.04.202417.04.20246.4Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget CVSS 6.4 · 17.04.20246.4Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget CVSS 6.4 · 17.04.202421.05.20246.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via custom_attributes CVSS 6.4 · 21.05.20245.3Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.3 - Form Submission Admin Email Bypass CVSS 5.3 · 21.05.202411.06.20246.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via onclick events CVSS 6.4 · 11.06.202417.07.20246.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 17.07.20246.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 17.07.202401.08.20246.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 01.08.202408.08.20246.5Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 - Authenticated (Contributor+) Arbitrary File Read CVSS 6.5 · 08.08.20246.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag CVSS 6.4 · 08.08.202412.08.20246.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets CVSS 6.4 · 12.08.202430.09.20246.4Element Pack Elementor Addons <= 5.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 30.09.202401.11.20245.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate CVSS 5.4 · 01.11.20246.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget CVSS 6.4 · 01.11.202404.11.20245.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Map Widget CVSS 5.4 · 04.11.20246.5Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting CVSS 6.5 · 04.11.202407.11.20246.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 07.11.202414.11.20246.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Cookie Consent' CVSS 6.4 · 14.11.202402.12.20246.4Element Pack Elementor Addons <= 5.10.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Lightbox Widget CVSS 6.4 · 02.12.202421.12.20244.3Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.12 - Missing Authorization CVSS 4.3 · 21.12.202407.01.20256.4Element Pack Lite - Addons for Elementor <= 5.10.14 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 07.01.202518.04.20256.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.28 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting CVSS 6.4 · 18.04.202525.04.20256.4Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.29 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 25.04.202530.05.20256.4Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting CVSS 6.4 · 30.05.202502.07.20256.4Element Pack Addons for Elementor <= 8.0.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute CVSS 6.4 · 02.07.202505.08.20255.4Element Pack Elementor Addons and Templates <= 8.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content CVSS 5.4 · 05.08.202520.10.20255.0Element Pack Addons for Elementor <= 8.2.5 - Authenticated (Subscriber+) Blind Server-Side Request Forgery CVSS 5.0 · 20.10.202517.11.20255.4Element Pack Addons for Elementor <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map widget CVSS 5.4 · 17.11.202516.01.20264.3Element Pack Elementor Addons <= 8.3.13 - Cross-Site Request Forgery CVSS 4.3 · 16.01.202614.02.20266.5Element Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary File Read CVSS 6.5 · 14.02.202623.03.20264.9Element Pack Elementor Addons <= 8.4.2 - Authenticated (Editor+) SQL Injection CVSS 4.9 · 23.03.202607.04.20266.4Element Pack Addons for Elementor <= 8.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Image Widget CVSS 6.4 · 07.04.202628.07.20265.3Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons <= 8.7.13 - Missing Authorization CVSS 5.3 · 28.07.202602.08.20266.4Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons < 8.7.13 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 02.08.202606.08.20265.3Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Injection CVSS 5.3 · 06.08.202608.08.20265.4Biggopti Library (Various Versions) - Cross-Site Scripting via display_id from Sigmative API CVSS 5.4 · 08.08.2026

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage100%
Open

0

Fixed

42

Get automatic notifications for all Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.9CVE-2024-30496

Element Pack Elementor Addons <= 5.5.3 - Authenticated (Contributor+) SQL Injection

Read the full analysis

Vulnerability Records

42 records
2026-08-08 00:00N/A
5.4
Medium
AnonymousYes
2026-08-06 00:15CVE-2026-0673
5.3
Medium
Drew Webber (mcdruid)Yes
2026-08-02 00:00CVE-2026-14817
6.4
Medium
Pierre RudloffYes
2026-07-28 00:00CVE-2026-65502
5.3
Medium
johskaYes
2026-04-07 19:36CVE-2026-4655
6.4
Medium
WebbernautYes
2026-03-23 00:00CVE-2026-40745
4.9
Medium
darooYes
2026-02-14 14:34CVE-2026-1793
6.5
Medium
Chiao-Lin Yu (Steven Meow)Yes
2026-01-16 00:00CVE-2025-31413
4.3
Medium
Arif ShaikhYes
2025-11-17 20:54CVE-2025-13196
5.4
Medium
zer0gh0stYes
2025-10-20 08:59CVE-2025-11536
5.0
Medium
LionTreeYes
Showing 1–10 of 42 reports
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons banner
Latestv8.8.2

Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons

bdthemes

Author

bdthemes

4.7(284)
94/100
Last Updated
2026-09-02 (11d ago)
Active Installs
100,000+
Downloads
6,498,667
Requires WP
6.8+
Requires PHP
7.4.0+
Tested up to
WP 7.1
Created
2019-09-19 (7y ago)

Element Pack Lite is a powerful Elementor addon that extends the Elementor page builder with advanced widgets, ready-made templates and design extensions. Build professional WordPress websites without writing code, using widgets that work directly inside the Elementor editor. Get Element Pack Advanced Elementor widgets A large collection of widgets for landing pages, business sites, portfolios and blogs: Pricing Table, Testimonial and Review Card Image Gallery, Image Accordion and Image Compare Team Member, Logo Grid and Brand Grid Countdown Timer, Business Hours and Progress Pie Social Feed, Twitter Grid and Facebook Feed Post Grid, Slider and Carousel widgets WooCommerce widgets Design fully customised shops inside Elementor: Product Grid and Product Carousel Product Category and Product Gallery Add to Cart and Product Slider Form integrations Style and display forms from the plugins you already use: Contact Form 7, WPForms and Ninja Forms Fluent Forms, Formidable Forms and Forminator Everest Forms and weForms Elementor extensions Extensions that add capability to any Elementor element: Wrapper Link, Tooltip and Floating Effects Cursor Effects, Grid Line and Backdrop Filter Equal Height, Transform Effects and Reading Progress Dark Mode, Cookie Consent and Scroll Button Ready-made templates Import complete page and section templates from the built-in template library and customise everything in Elementor. Third-party integrations Widgets for Tutor LMS, GiveWP, Events Calendar and more, so your existing plugins fit your design. Documentation and support Full documentation is available at elementpack.pro. For help, visit our support centre. Common Issues and Solutions: 🐣 Editor fails to load Ans. It is due to your server PHP setting. You can increase PHP memory limit from wp-config.php file or php.ini file View Documentation Need Help? Have a feature suggestion? Share it with us on our Feature Suggestion Page. For assistance, Contact us 💌 or check out our Tutorials. Checkout our other Plugins 👑 Explore the best free addons for Elementor and Gutenberg to boost your site with advanced blocks, sliders and eCommerce tools. Element Pack – Build responsive websites from scratch with an all-rounder package of 300+ widgets and 2700+ ready-to-use assets for Elementor. Prime Slider – The revolutionary slider builder addon for Elementor with a next-gen superb interface and 50+ unique slider designs. Ultimate Post Kit – Best blogging addon for building a quality blogging website with fine-tuned post layouts, carousels, sliders and lists. Ultimate Store Kit – The only eCommerce addon for answering all your online store design problems in one package for WooCommerce and EDD. Pixel Gallery – The first Elementor-based WordPress gallery addon offering 60+ flexible and customizable gallery builder widgets. ZoloBlocks – Mind-blowing dynamic block plugin for Gutenberg with powerful and advanced features offering a greater web design experience. Augmented Reality Viewer – Bring your products to life with immersive 3D and AR experiences directly inside your WordPress website. Dark Reader – Instantly transform your website into a sleek, eye-friendly dark mode experience with smooth and elegant styling. Instant Image Generator – Generate AI-powered images or import visuals instantly from popular platforms like Unsplash, Openverse, Pixabay, Pexels and Giphy all from one place. Live Copy Paste – Seamlessly copy and paste sections, widgets and entire pages across domains with zero hassle. One Accessibility – Make your website inclusive and accessible to everyone with essential accessibility enhancements and compliance-ready tools. QR Code Generator & Scanner – Create and manage dynamic QR codes directly from your WordPress dashboard for smarter engagement and tracking. Smart Admin Assistant – Enhance your WordPress dashboard with productivity-focused tools and smart site management features. Spin Wheel – Engage visitors with an interactive spinning wheel that offers discounts, coupons and promotional rewards. Swift Checkout for WooCommerce – Simplify the WooCommerce checkout process to improve user experience and boost conversion rates. Visit BdThemes to learn about our services, Elementor page builder-based products, informative blogs and documentation. External services This plugin relies on the third-party services listed below. Each entry states what the service is used for, what data is sent and when it is sent. Element Pack template library (BdThemes) Used to list and import the ready-made Elementor templates offered inside the editor. Data sent: when a logged-in administrator opens the template library or imports a template, the plugin requests the template index and the selected template’s JSON from elementpack.pro. The setup wizard’s starter kits are downloaded the same way, from templates.elementpack.pro, when an administrator chooses to import one. No site content, user data or credentials are transmitted. Service provided by BdThemes. Terms: https://elementpack.pro/terms-and-conditions/ Privacy Policy: https://elementpack.pro/privacy-policy/ BdThemes product feed Used to display BdThemes product news on the plugin’s own admin dashboard page. Data sent: a plain read request to dashboard.bdthemes.io when an administrator loads the Element Pack settings screen. No personal data is transmitted. Service provided by BdThemes. Terms: https://elementpack.pro/terms-and-conditions/ Privacy Policy: https://bdthemes.com/privacy-policy/ Google reCAPTCHA Used to verify form submissions in the Contact Form and User Register widgets, and only when you have entered reCAPTCHA keys and enabled the option on the widget. Data sent: the visitor’s reCAPTCHA response token, your reCAPTCHA secret key and the visitor’s IP address are sent to google.com when a protected form is submitted. Service provided by Google. Terms: https://policies.google.com/terms Privacy Policy: https://policies.google.com/privacy Google Docs Viewer Used by the Document Viewer widget to render documents that cannot be displayed natively. Data sent: the URL of the document you configure is embedded in an iframe pointing at docs.google.com, so the document URL is disclosed to Google and the visitor’s browser contacts Google directly when the page is viewed. Service provided by Google. Terms: https://policies.google.com/terms Privacy Policy: https://policies.google.com/privacy X (Twitter) API Used by the Twitter Grid widget to fetch tweets for a configured account. Data sent: your Twitter API credentials and the configured screen name are sent to api.twitter.com when the widget renders and its cache has expired. Used only when you have entered Twitter API credentials. Service provided by X Corp. Terms: https://x.com/en/tos Privacy Policy: https://x.com/en/privacy Facebook Graph API Used by the Facebook Feed widget to fetch posts and avatars for a configured page. Data sent: your Facebook access token and the configured page ID are sent to graph.facebook.com when the widget renders and its cache has expired. Used only when you have entered a Facebook access token. Service provided by Meta Platforms. Terms: https://www.facebook.com/terms.php Privacy Policy: https://www.facebook.com/privacy/policy/ Mapbox Used by the Open Street Map widget to load map tiles, and only when you have entered a Mapbox access token. Data sent: the visitor’s browser requests map tiles from api.mapbox.com using your access token when a page containing the map is viewed. Service provided by Mapbox. Terms: https://www.mapbox.com/legal/tos Privacy Policy: https://www.mapbox.com/legal/privacy CoinGecko Used to retrieve cryptocurrency market data for the crypto currency feature. Data sent: the requested currency, coin identifiers and paging options are sent to api.coingecko.com when the data is refreshed. No personal data is transmitted. Service provided by CoinGecko. Terms: https://www.coingecko.com/en/terms Privacy Policy: https://www.coingecko.com/en/privacy Calendly Used by the Calendly widget to embed a scheduling page. Data sent: the Calendly script is loaded from calendly.com and the visitor’s browser contacts Calendly directly when a page containing the widget is viewed. Service provided by Calendly. Terms: https://calendly.com/legal Privacy Policy: https://calendly.com/privacy OpenStreetMap Used by the Open Street Map widget to load map tiles when no Mapbox token is configured. Data sent: the visitor’s browser requests map tiles directly from openstreetmap.org when a page containing the map is viewed. Service provided by the OpenStreetMap Foundation. Terms: https://osmfoundation.org/wiki/Terms_of_Use Privacy Policy: https://osmfoundation.org/wiki/Privacy_Policy Facebook JavaScript SDK Used by the Facebook access-token generator in the plugin’s admin settings, so an administrator can obtain a token for the Facebook Feed widget. Data sent: the Facebook SDK is loaded from connect.facebook.net and the administrator’s browser communicates with Facebook only while that admin screen is open. Service provided by Meta Platforms. Terms: https://www.facebook.com/terms.php Privacy Policy: https://www.facebook.com/privacy/policy/ Google Chart API (QR codes) Used by the Social Share widget to render a QR code for the current page when the QR share option is enabled. Data sent: the URL being shared is sent to chart.apis.google.com to generate the QR image. Service provided by Google. Terms: https://policies.google.com/terms Privacy Policy: https://policies.google.com/privacy Social share counters Used by the Social Share widget, and only when the share-counter option is enabled for a network. The counter is not shown by default. Data sent: the URL of the page being viewed is sent to that network’s public share-count endpoint from the visitor’s browser when the page loads. No personal data is transmitted. Networks with share counters, and their legal pages: * Facebook – https://www.facebook.com/terms.php | https://www.facebook.com/privacy/policy/ * LinkedIn – https://www.linkedin.com/legal/user-agreement | https://www.linkedin.com/legal/privacy-policy * Pinterest – https://policy.pinterest.com/terms-of-service | https://policy.pinterest.com/privacy-policy * Tumblr – https://www.tumblr.com/policy/terms-of-service | https://www.tumblr.com/privacy_policy * Buffer – https://buffer.com/legal | https://buffer.com/privacy * Pocket – https://getpocket.com/tos | https://www.mozilla.org/privacy/ * VK – https://vk.com/terms | https://vk.com/privacy * OK – https://ok.ru/regulations * Mail.Ru – https://help.mail.ru/legal/terms/common/ua | https://help.mail.ru/legal/terms/common/privacy Vimeo oEmbed Used by the bundled UIkit library’s video component. When a Vimeo video is embedded in a widget, UIkit asks Vimeo for the video’s dimensions so the player can be sized correctly. Data sent: the Vimeo video URL is sent to vimeo.com/api/oembed.json from the visitor’s browser when a page containing that video is viewed. The request is made without credentials and no personal data is transmitted. Service provided by Vimeo. Terms: https://vimeo.com/terms Privacy Policy: https://vimeo.com/privacy WordPress.org Plugin API Used by the setup wizard and the plugin-recommendation screens to look up the name, icon and download link of the free plugins offered there. Data sent: the slug of the plugin being looked up is sent to api.wordpress.org when an administrator opens one of those screens or chooses to install a plugin. No personal data is transmitted. Service provided by the WordPress Foundation. Terms: https://wordpress.org/about/terms/ Privacy Policy: https://wordpress.org/about/privacy/ Source code The human-readable source for this plugin, together with the build tooling used to generate the minified assets in assets/js and assets/css, is publicly available at: https://github.com/bdthemes/bdthemes-element-pack-lite This plugin bundles the following third-party libraries, unmodified, under their own licences. Each is the upstream distribution of the named project: bdt-uikit 3.21.7 (UIkit) – https://getuikit.com/ Leaflet – https://leafletjs.com/ goodshare.js 4.1.2 – https://github.com/koddr/goodshare.js Popper – https://popper.js.org/ Tippy.js – https://atomiks.github.io/tippyjs/ anime.js 3.2.1 – https://animejs.com/ Chart.js – https://www.chartjs.org/ cookieconsent 3.1.0 – https://github.com/osano/cookieconsent vanilla-tilt.js – https://micku7zu.github.io/vanilla-tilt.js/ image-compare-viewer – https://github.com/kylewetton/image-compare-viewer parallax.js – https://matthew.wagerfield.com/parallax/ Granim.js – https://sarcadass.github.io/granim.js/ ztext.js – https://bennettfeely.com/ztext/ Minify (matthiasmullie/minify) – https://github.com/matthiasmullie/minify TwitterOAuth – https://github.com/abraham/twitteroauth Parsedown – https://parsedown.org/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C