PLUGIN SECURITY
Is Element Pack Lite - Addons for Elementor safe?
Elementor addons with 300+ Elementor widgets, WooCommerce Elementor elements, Elementor templates, Elementor mega menu, Elementor header footer builde …
What this plugin does
- Slug:
bdthemes-element-pack-lite - Author: bdthemes
- 100000+ active installs
- 94/100 rating (284 reviews on wordpress.org)
- 6488747 all-time downloads
- On WordPress.org since 2019-09-19
elementor addonselementor templateselementor widgetswidgets for elementorWooCommerce widgets
Maintenance status
- Last updated: 2026-09-02 9:20am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4.0+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
44 known CVEs on file for Element Pack Lite - Addons for Elementor.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] <= 8.7.14 (unfixed) | — | Unknown | < 8.7.14 | 8.7.14 | 2026-08-08 | — |
| CVE-2026-0673 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.3.16 | Improper Neutralization of CRLF Sequences ('CRLF Injection') | Medium 5.3 | < 8.3.16 | 8.3.16 | 2026-08-06 | — |
| CVE-2026-14817 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.7.13 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 8.7.13 | 8.7.13 | 2026-08-02 | — |
| CVE-2026-65502 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.7.14 | Authentication Bypass by Spoofing | Medium 5.3 | < 8.7.14 | 8.7.14 | 2026-07-28 | — |
| CVE-2026-40745 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.5.0 | — | High 7.6 | < 8.5.0 | 8.5.0 | 2026-03-23 | — |
| CVE-2025-31413 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.3.14 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 8.3.14 | 8.3.14 | 2026-01-16 | — |
| CVE-2025-13196 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.3.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 8.3.5 | 8.3.5 | 2025-11-17 | — |
| CVE-2025-11536 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.2.6 | Server-Side Request Forgery (SSRF) | Medium 5.0 | < 8.2.6 | 8.2.6 | 2025-10-20 | — |
+ 44 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-12851 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.15 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.10.15 | 5.10.15 | 2025-01-07 | — |
| CVE-2024-11852 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.13 | Missing Authorization | Medium 4.3 | < 5.10.13 | 5.10.13 | 2024-12-21 | — |
| CVE-2024-9058 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.10.6 | 5.10.6 | 2024-12-02 | — |
| CVE-2024-10980 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.10.3 | 5.10.3 | 2024-11-14 | — |
| CVE-2024-10493 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.10.3 | 5.10.3 | 2024-11-07 | — |
| CVE-2024-9657 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.10.3 | 5.10.3 | 2024-11-04 | — |
| CVE-2024-9867 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.10.3 | 5.10.3 | 2024-11-04 | — |
| CVE-2024-10310 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.10.2 | 5.10.2 | 2024-11-01 | — |
| CVE-2024-9868 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.10.2 | 5.10.2 | 2024-11-01 | — |
| CVE-2024-47392 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.7.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 5.7.6 | 5.7.6 | 2024-09-30 | — |
| CVE-2024-7247 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.7.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.7.3 | 5.7.3 | 2024-08-12 | — |
| CVE-2024-4360 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.7.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.7.7 | 5.7.7 | 2024-08-08 | — |
| CVE-2024-4359 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.7.3 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | Medium 6.5 | < 5.7.3 | 5.7.3 | 2024-08-08 | — |
| CVE-2024-4643 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.12 | 5.6.12 | 2024-08-01 | — |
| CVE-2024-39667 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.12 | 5.6.12 | 2024-08-01 | — |
| CVE-2024-5554 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.6.12 | 5.6.12 | 2024-07-17 | — |
| CVE-2024-5555 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.6.6 | 5.6.6 | 2024-07-17 | — |
| CVE-2024-3925 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.12 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.12 | 5.6.12 | 2024-06-11 | — |
| CVE-2024-3927 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.4 | Improper Protection of Alternate Path | Medium 5.3 | < 5.6.4 | 5.6.4 | 2024-05-21 | — |
| CVE-2024-3926 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.2 | 5.6.2 | 2024-05-21 | — |
| CVE-2024-1426 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.1 | 5.6.1 | 2024-04-17 | — |
| CVE-2024-1429 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.1 | 5.6.1 | 2024-04-17 | — |
| CVE-2024-32572 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.6.1 | 5.6.1 | 2024-04-16 | — |
| CVE-2024-2966 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.0 | Exposure of Sensitive Information to an Unauthorized Actor | High 7.5 | < 5.6.0 | 5.6.0 | 2024-04-10 | — |
| CVE-2024-0837 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.3.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.3.3 | 5.3.3 | 2024-04-05 | — |
| CVE-2024-1428 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.5.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.5.4 | 5.5.4 | 2024-04-05 | — |
| CVE-2024-30496 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.5.4 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.5 | < 5.5.4 | 5.5.4 | 2024-03-28 | — |
| CVE-2024-30185 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.5.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 5.5.4 | 5.5.4 | 2024-03-25 | — |
| CVE-2024-24840 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.4.12 | Missing Authorization | Medium 4.3 | < 5.4.12 | 5.4.12 | 2024-02-02 | — |
| CVE-2023-33999 | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.2.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 5.2.1 | 5.2.1 | 2023-07-18 | — |
| — | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.29 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.10.29 | 5.10.29 | 0000-00-00 | — |
| — | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.30 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 5.10.30 | 5.10.30 | 0000-00-00 | — |
| — | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.11.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 5.11.3 | 5.11.3 | 0000-00-00 | — |
| — | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.1.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 8.1.0 | 8.1.0 | 0000-00-00 | — |
| — | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.1.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 8.1.6 | 8.1.6 | 0000-00-00 | — |
| — | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.3.18 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Medium 6.5 | < 8.3.18 | 8.3.18 | 0000-00-00 | — |
| — | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.5.0 | — | Unknown | < 8.5.0 | 8.5.0 | 0000-00-00 | — |
| CVE-2025-1457 | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) < 5.10.29 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | — | Unknown | < 5.10.29 | 5.10.29 | — | — |
| CVE-2025-1458 | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) < 5.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | < 5.10.30 | 5.10.30 | — | — |
| CVE-2025-5292 | Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder < 5.11.3 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | — | Unknown | < 5.11.3 | 5.11.3 | — | — |
| CVE-2025-5944 | Element Pack Addons for Elementor < 8.1.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute | — | Unknown | < 8.1.0 | 8.1.0 | — | — |
| CVE-2025-8100 | Element Pack Elementor Addons and Templates < 8.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content | — | Unknown | < 8.1.6 | 8.1.6 | — | — |
| CVE-2026-1793 | Element Pack Addons for Elementor < 8.3.18 - Authenticated (Contributor+) Arbitrary File Read | — | Unknown | < 8.3.18 | 8.3.18 | — | — |
| CVE-2026-4655 | Element Pack Addons for Elementor < 8.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Image Widget | — | Unknown | < 8.5.0 | 8.5.0 | — | — |
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder — 2000000+ active installs — 98/100 (2525) — max PHP 8.4
- Essential Addons for Elementor – Popular Elementor Templates & Widgets — 1000000+ active installs — 98/100 (4114) — max PHP 8.4
- ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor — 1000000+ active installs — 98/100 (2037) — max PHP 8.4
- Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools — 600000+ active installs — 98/100 (1677) — max PHP 8.4
- Royal Addons for Elementor – Addons and Templates Kit for Elementor — 600000+ active installs — 96/100 (611)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.