CVE · Medium

CVE-2025-31413 — Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.3.14

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-31413 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.3.14 Cross-Site Request Forgery (CSRF) Medium 4.3 < 8.3.14 8.3.14 2026-01-16

CVE-2025-31413

The Element Pack Addons for Elementor WordPress plugin contains a weakness in its security checks, allowing any user to initiate certain actions without needing permission, provided they can deceive an administrator into taking a specific step like clicking on a particular link. This flaw is present in all versions of the plugin up to and including 8.3.13. The issue stems from inadequate validation of security tokens used by the plugin's functions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.