CVE-2026-40721
Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.
Source: CVE.org
PLUGIN SECURITY
Elementor addons with 300+ Elementor widgets, WooCommerce Elementor elements, Elementor templates, Elementor mega menu, Elementor header footer builde …
bdthemes-element-packelementor addonselementor templateselementor widgetswidgets for elementorWooCommerce widgets
5 known CVEs on file for Bdthemes Element Pack. Reported between 2024 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-40721 | Element Pack Pro [bdthemes-element-pack] < 9.1.0 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | High 7.5 | < 9.1.0 | 9.1.0 | 2026-06-17 | — |
| CVE-2025-46257 | Element Pack Pro [bdthemes-element-pack] < 8.0.0 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 8.0.0 | 8.0.0 | 2025-05-16 | — |
| CVE-2025-46258 | Element Pack Pro [bdthemes-element-pack] < 8.0.0 | Missing Authorization | Medium 5.4 | < 8.0.0 | 8.0.0 | 2025-05-16 | — |
| CVE-2024-2455 | Element Pack Pro [bdthemes-element-pack] < 7.9.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 7.9.1 | 7.9.1 | 2024-07-31 | — |
| CVE-2024-33568 | Element Pack Pro [bdthemes-element-pack] < 7.19.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.5 | < 7.19.3 | 7.19.3 | 2024-04-25 | — |
Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.
Source: CVE.org
The Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.21.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.
Source: Wordfence
The Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.21.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Source: Wordfence
The Element Pack - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget wrapper link URL in all versions up to, and including, 7.9.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source: CVE.org
The Element Pack Pro - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.19.2. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Source: Wordfence
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.