WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Bdthemes Element Pack safe?

Elementor addons with 300+ Elementor widgets, WooCommerce Elementor elements, Elementor templates, Elementor mega menu, Elementor header footer builde …

What this plugin does

  • Slug: bdthemes-element-pack
  • Author: bdthemes
  • 100000+ active installs
  • 94/100 rating (284 reviews on wordpress.org)
  • 6250415 all-time downloads
  • On WordPress.org since 2019-09-19

elementor addonselementor templateselementor widgetswidgets for elementorWooCommerce widgets

Maintenance status

  • Last updated: 2026-07-21 10:30am GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 7.4.0+

Known vulnerabilities

5 known CVEs on file for Bdthemes Element Pack. Reported between 2024 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-40721 Element Pack Pro [bdthemes-element-pack] < 9.1.0 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 7.5 < 9.1.0 9.1.0 2026-06-17
CVE-2025-46257 Element Pack Pro [bdthemes-element-pack] < 8.0.0 Cross-Site Request Forgery (CSRF) Medium 4.3 < 8.0.0 8.0.0 2025-05-16
CVE-2025-46258 Element Pack Pro [bdthemes-element-pack] < 8.0.0 Missing Authorization Medium 5.4 < 8.0.0 8.0.0 2025-05-16
CVE-2024-2455 Element Pack Pro [bdthemes-element-pack] < 7.9.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 7.9.1 7.9.1 2024-07-31
CVE-2024-33568 Element Pack Pro [bdthemes-element-pack] < 7.19.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.5 < 7.19.3 7.19.3 2024-04-25

CVE-2026-40721

Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.

Source: CVE.org

CVE-2025-46257

The Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.21.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

CVE-2025-46258

The Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.21.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

Source: Wordfence

CVE-2024-2455

The Element Pack - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget wrapper link URL in all versions up to, and including, 7.9.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Source: CVE.org

CVE-2024-33568

The Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.19.2. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.