WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Element Pack Lite - Addons for Elementor safe?

Elementor addons with 300+ Elementor widgets, WooCommerce Elementor elements, Elementor templates, Elementor mega menu, Elementor header footer builde …

What this plugin does

  • Slug: bdthemes-element-pack-lite
  • Author: bdthemes
  • 100000+ active installs
  • 94/100 rating (284 reviews on wordpress.org)
  • 6281469 all-time downloads
  • On WordPress.org since 2019-09-19

elementor addonselementor templateselementor widgetswidgets for elementorWooCommerce widgets

Maintenance status

  • Last updated: 2026-07-21 10:30am GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 7.4.0+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

41 known CVEs on file for Element Pack Lite - Addons for Elementor.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-40745 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.5.0 High 7.6 < 8.5.0 8.5.0 2026-03-23
CVE-2025-31413 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.3.14 Cross-Site Request Forgery (CSRF) Medium 4.3 < 8.3.14 8.3.14 2026-01-16
CVE-2025-13196 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.3.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 8.3.5 8.3.5 2025-11-17
CVE-2025-11536 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.2.6 Server-Side Request Forgery (SSRF) Medium 5.0 < 8.2.6 8.2.6 2025-10-20
CVE-2024-12851 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.15 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.10.15 5.10.15 2025-01-07
CVE-2024-11852 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.13 Missing Authorization Medium 4.3 < 5.10.13 5.10.13 2024-12-21
CVE-2024-9058 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.10.6 5.10.6 2024-12-02
CVE-2024-10980 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.10.3 5.10.3 2024-11-14

CVE-2026-40745

The Element Pack Elementor Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: Wordfence

CVE-2025-31413

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.13. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

CVE-2025-13196

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Street Map widget's marker content parameter in all versions up to, and including, 8.3.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the render function. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2025-11536

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8.2.5 via the wp_ajax_import_elementor_template action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Source: CVE.org

CVE-2024-12851

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes parameter of the Cookie Consent Widget in all versions up to, and including, 5.10.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-11852

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_layouts() function in all versions up to, and including, 5.10.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain a detailed listing of layout templates.

Source: CVE.org

CVE-2024-9058

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lightbox widget in all versions up to, and including, 5.10.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-10980

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Cookie Consent block in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

+ 33 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10493 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.10.3 5.10.3 2024-11-07
CVE-2024-9657 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.10.3 5.10.3 2024-11-04
CVE-2024-9867 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.10.3 5.10.3 2024-11-04
CVE-2024-10310 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.10.2 5.10.2 2024-11-01
CVE-2024-9868 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.10.2 5.10.2 2024-11-01
CVE-2024-47392 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.7.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 5.7.6 5.7.6 2024-09-30
CVE-2024-7247 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.7.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.7.3 5.7.3 2024-08-12
CVE-2024-4360 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.7.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.7.7 5.7.7 2024-08-08
CVE-2024-4359 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.7.3 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Medium 6.5 < 5.7.3 5.7.3 2024-08-08
CVE-2024-4643 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.6.12 5.6.12 2024-08-01
CVE-2024-39667 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.6.12 5.6.12 2024-08-01
CVE-2024-5554 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.6.12 5.6.12 2024-07-17
CVE-2024-5555 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.6.6 5.6.6 2024-07-17
CVE-2024-3925 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.6.12 5.6.12 2024-06-11
CVE-2024-3927 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.4 Improper Protection of Alternate Path Medium 5.3 < 5.6.4 5.6.4 2024-05-21
CVE-2024-3926 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.6.2 5.6.2 2024-05-21
CVE-2024-1426 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.6.1 5.6.1 2024-04-17
CVE-2024-1429 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.6.1 5.6.1 2024-04-17
CVE-2024-32572 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.6.1 5.6.1 2024-04-16
CVE-2024-2966 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.0 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 5.6.0 5.6.0 2024-04-10
CVE-2024-0837 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.3.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.3.3 5.3.3 2024-04-05
CVE-2024-1428 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.5.4 5.5.4 2024-04-05
CVE-2024-30496 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.5.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.5 < 5.5.4 5.5.4 2024-03-28
CVE-2024-30185 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 5.5.4 5.5.4 2024-03-25
CVE-2024-24840 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.4.12 Missing Authorization Medium 4.3 < 5.4.12 5.4.12 2024-02-02
CVE-2023-33999 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.2.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 5.2.1 5.2.1 2023-07-18
CVE-2025-1457 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.10.29 5.10.29 0000-00-00
CVE-2025-1458 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.10.30 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.10.30 5.10.30 0000-00-00
CVE-2025-5292 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.11.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 5.11.3 5.11.3 0000-00-00
CVE-2025-5944 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.1.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 8.1.0 8.1.0 0000-00-00
CVE-2025-8100 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.1.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 8.1.6 8.1.6 0000-00-00
CVE-2026-1793 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.3.18 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.5 < 8.3.18 8.3.18 0000-00-00
CVE-2026-4655 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.5.0 Unknown < 8.5.0 8.5.0 0000-00-00

CVE-2024-10493

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Lightbox' block in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2024-9657

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip' parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-9867

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Open Map Widget' marker_content parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-10310

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Gallery Widget 'image_title' parameter in all versions up to, and including, 5.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-9868

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate Widget 'url' parameter in all versions up to, and including, 5.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-47392

The Element Pack Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2024-7247

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Gallery and Countdown widgets in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-4360

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user supplied attributes like 'title_tag'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-4359

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 5.7.2 via the SVG widget and a lack of sufficient file validation in the render_svg function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

Source: CVE.org

CVE-2024-4643

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘end_redirect_link’ parameter in versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-39667

<p>WordPress Element Pack Elementor Addons Plugin <= 5.6.11 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Element Pack Elementor Addons</p><p>Link: https://wordpress.org/plugins/bdthemes-element-pack-lite/#developers</p><p>Affected Version <= 5.6.11</p><p>Fixed in version 5.6.12 </p>

Source: Patchstack

CVE-2024-5554

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘onclick_event’ parameter in all versions up to, and including, 5.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-39667 is likely a duplicate of this issue.

Source: Wordfence

CVE-2024-5555

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘social-link-title’ parameter in all versions up to, and including, 5.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-3925

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, and including, 5.6.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2024-3927

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to the plugin not properly checking for all variations of an administrators emails. This makes it possible for unauthenticated attackers to bypass the restriction using a +value when submitting the contact form.

Source: CVE.org

CVE-2024-3926

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes value in widgets in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-1426

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ attribute of the Price List widget in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-1429

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tab_link’ attribute of the Panel Slider widget in all versions up to, and including, 5.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32572 is likely a duplicate of this or CVE-2024-1426.

Source: Wordfence

CVE-2024-32572

<p>WordPress Element Pack Elementor Addons Plugin <= 5.6.0 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: Element Pack Elementor Addons</p><p>Link: https://wordpress.org/plugins/bdthemes-element-pack-lite/#developers</p><p>Affected Version <= 5.6.0</p><p>Fixed in version 5.6.1 </p>

Source: Patchstack

CVE-2024-2966

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.5.6 via the element_pack_ajax_search function. This makes it possible for unauthenticated attackers to extract sensitive data including password protected post details.

Source: CVE.org

CVE-2024-0837

Update the WordPress Element Pack Elementor Addons plugin to the latest available version (at least 5.3.3). Webbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Element Pack Elementor Addons Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 5.3.3. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2024-1428

The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘element_pack_wrapper_link’ attribute of the Trailer Box widget in all versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-30496

Update the WordPress Element Pack Elementor Addons plugin to the latest available version (at least 5.5.4). Rafie Muhammad (Patchstack) discovered and reported this SQL Injection vulnerability in WordPress Element Pack Elementor Addons Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 5.5.4. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2024-30185

Update the WordPress Element Pack Elementor Addons plugin to the latest available version (at least 5.5.4). Abu Hurayra discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Element Pack Elementor Addons Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 5.5.4. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2024-24840

Update the WordPress Element Pack Elementor Addons plugin to the latest available version (at least 5.4.12). Abu Hurayra discovered and reported this Broken Access Control vulnerability in WordPress Element Pack Elementor Addons Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 5.4.12. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2023-33999

Update the WordPress Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin to the latest available version (at least 5.2.1). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 5.2.1.

Source: Patchstack

CVE-2025-1457

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Wrapper Link, Countdown and Gallery widgets in all versions up to, and including, 5.10.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2025-1458

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like Dual Button, Creative Button, Image Stack and more in all versions up to, and including, 5.10.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2025-5292

The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content’ parameter in all versions up to, and including, 5.11.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2025-5944

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-caption’ attribute in all versions up to, and including, 8.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2025-8100

The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content' parameter in versions up to, and including, 8.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: Wordfence

CVE-2026-1793

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the SVG widget and a lack of sufficient file validation in the 'render_svg' function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

Source: euvd.enisa.europa.eu

CVE-2026-4655

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Image Widget in versions up to and including 8.4.2. This is due to insufficient input sanitization and output escaping on SVG content fetched from remote URLs in the render_svg() function. The function fetches SVG content using wp_safe_remote_get() and then directly echoes it to the page without any sanitization, only applying a preg_replace() to add attributes to the SVG tag which does not remove malicious event handlers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary JavaScript in SVG files that will execute whenever a user accesses a page containing the malicious widget.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.