Pricing
Case studies
Login
Start trial
Element Pack Elementor Addons
bdthemes
Developer
8.5.1
Latest version
100,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
36 patched
2 Mitigation rules
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget vulnerability
<= 5.10.1
03/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget vulnerability
<= 5.6.0
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget vulnerability
<= 5.6.0
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.6.11
02/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Open Map Widget vulnerability
<= 5.10.2
02/02/2026
Contributor+ Stored XSS vulnerability
< 5.10.3
30/01/2026
Cross Site Request Forgery (CSRF) vulnerability
<= 8.3.13
16/01/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map widget vulnerability
<= 8.3.4
18/11/2025
Authenticated (Subscriber+) Blind Server-Side Request Forgery vulnerability
<= 8.2.5
20/10/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content vulnerability
<= 8.1.5
05/08/2025
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute vulnerability
8.0.0
02/07/2025
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability
<= 5.11.2
30/05/2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.10.29
25/04/2025
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability
<= 5.10.28
19/04/2025
WordPress Element Pack Lite - Addons for Elementor plugin <= 5.10.14 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.10.14
07/01/2025
Missing Authorization vulnerability
<= 5.10.12
23/12/2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Lightbox Widget vulnerability
<= 5.10.5
02/12/2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability
<= 5.10.2
05/11/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.10.1
01/11/2024
Cross Site Scripting (XSS) vulnerability
<= 5.7.5
30/09/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets vulnerability
<= 5.7.2
13/08/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag vulnerability
<= 5.7.6
09/08/2024
Authenticated (Contributor+) Arbitrary File Read vulnerability
<= 5.7.2
09/08/2024
Cross Site Scripting (XSS) vulnerability
<= 5.6.11
01/08/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.6.5
18/07/2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 5.6.11
11/06/2024
Form Submission Admin Email Bypass vulnerability
<= 5.6.3
22/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via custom_attributes vulnerability
<= 5.6.1
22/05/2024
Cross Site Scripting (XSS) vulnerability
<= 5.6.0
16/04/2024
Sensitive Information Exposure via element_pack_ajax_search vulnerability
<= 5.5.6
15/04/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget vulnerability
<= 5.5.3
10/04/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget vulnerability
<= 5.3.2
08/04/2024
SQL Injection vulnerability
<= 5.5.3
28/03/2024
Cross Site Scripting (XSS) vulnerability
<= 5.5.3
25/03/2024
Broken Access Control on Duplicate Post vulnerability
<= 5.4.11
02/02/2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 5.2.0
18/07/2023