ElementCamp

ElementCamp has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 6.5 out of 10. 2026 was the busiest year with 2 disclosures.

The most common weakness is Missing Authorization, behind 1 of the records (50%). Other recurring categories include SQL Injection.

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.

2 independent researchers contributed these findings, one record each. ElementCamp is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all ElementCamp vulnerabilities before they are exploited.

Most severe open issueCVSS 6.5CVE-2026-2503

ElementCamp <= 2.3.6 - Authenticated (Author+) SQL Injection via 'meta_query[compare]' Parameter

Read the full analysis

Vulnerability Records

2 records
ElementCamp banner
Latestv2.3.8

ElementCamp

wpdive

Author

wpdive

5.0(1)
100/100
Last Updated
2026-04-22 (5mo ago)
Active Installs
1,000+
Downloads
5,610
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 6.9.7
Created
2025-01-13 (2y ago)

ElementCamp is a lightweight and powerful plugin that extends Elementor’s capabilities by adding a custom widget. It’s perfect for enhancing the design and functionality of your WordPress website. Features: – Fully compatible with Elementor page builder. – Adds a custom widget for dynamic and creative content display. – Easy to use and customize. How to use: 1. Install and activate the plugin. 2. Ensure Elementor is installed and active. 3. Go to the Elementor editor and look for the “ElementCamp Widget” under the “General” category. 4. Drag, drop, and customize! License This plugin is licensed under the GPLv2 or later. See the GPLv2 License for details.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C