CVE · Medium

CVE-2025-46257 — Element Pack Pro [bdthemes-element-pack] < 8.0.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-46257 Element Pack Pro [bdthemes-element-pack] < 8.0.0 Cross-Site Request Forgery (CSRF) Medium 4.3 < 8.0.0 8.0.0 2025-05-16

CVE-2025-46257

The Element Pack Pro plugin for WordPress has a security flaw that allows malicious individuals to deceive administrators into executing unintended actions, resulting from inadequate validation of authentication tokens in certain functions across all versions up to 7.21.0. This vulnerability can be exploited by an attacker who tricks an administrator into clicking on a link, thereby bypassing normal access controls. The issue arises from the plugin's failure to properly verify the authenticity of requests.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.