ElementCamp
ElementCamp has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 6.5 out of 10. 2026 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 1 of the records (50%). Other recurring categories include SQL Injection.
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
2 independent researchers contributed these findings, one record each. ElementCamp is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-2503ElementCamp <= 2.3.6 - Authenticated (Author+) SQL Injection via 'meta_query[compare]' Parameter
Read the full analysisVulnerability Records

ElementCamp
Author
wpdive
ElementCamp is a lightweight and powerful plugin that extends Elementor’s capabilities by adding a custom widget. It’s perfect for enhancing the design and functionality of your WordPress website. Features: – Fully compatible with Elementor page builder. – Adds a custom widget for dynamic and creative content display. – Easy to use and customize. How to use: 1. Install and activate the plugin. 2. Ensure Elementor is installed and active. 3. Go to the Elementor editor and look for the “ElementCamp Widget” under the “General” category. 4. Drag, drop, and customize! License This plugin is licensed under the GPLv2 or later. See the GPLv2 License for details.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C