Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Element Pack Elementor Addons
bdthemes
Developer
8.3.5
Latest version
100,000
Installations
2 days ago
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
29 fixed
2 Mitigation rules
Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map widget vulnerability
<= 8.3.4
13 hours ago
Authenticated (Subscriber+) Blind Server-Side Request Forgery vulnerability
<= 8.2.5
Oct 20, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content vulnerability
<= 8.1.5
Aug 5, 2025
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute vulnerability
8.0.0
Jul 2, 2025
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability
<= 5.11.2
May 30, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.10.29
Apr 25, 2025
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability
<= 5.10.28
Apr 19, 2025
WordPress Element Pack Lite - Addons for Elementor plugin <= 5.10.14 - Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.10.14
Jan 7, 2025
Missing Authorization vulnerability
<= 5.10.12
Dec 23, 2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Lightbox Widget vulnerability
<= 5.10.5
Dec 2, 2024
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting vulnerability
<= 5.10.2
Nov 5, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.10.1
Nov 1, 2024
Cross Site Scripting (XSS) vulnerability
<= 5.7.5
Sep 30, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets vulnerability
<= 5.7.2
Aug 13, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag vulnerability
<= 5.7.6
Aug 9, 2024
Authenticated (Contributor+) Arbitrary File Read vulnerability
<= 5.7.2
Aug 9, 2024
Cross Site Scripting (XSS) vulnerability
<= 5.6.11
Aug 1, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.6.5
Jul 18, 2024
Authenticated Stored Cross-Site Scripting vulnerability
<= 5.6.11
Jun 11, 2024
Form Submission Admin Email Bypass vulnerability
<= 5.6.3
May 22, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via custom_attributes vulnerability
<= 5.6.1
May 22, 2024
Cross Site Scripting (XSS) vulnerability
<= 5.6.0
Apr 16, 2024
Sensitive Information Exposure via element_pack_ajax_search vulnerability
<= 5.5.6
Apr 15, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget vulnerability
<= 5.5.3
Apr 10, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget vulnerability
<= 5.3.2
Apr 8, 2024
SQL Injection vulnerability
<= 5.5.3
Mar 28, 2024
Cross Site Scripting (XSS) vulnerability
<= 5.5.3
Mar 25, 2024
Broken Access Control on Duplicate Post vulnerability
<= 5.4.11
Feb 2, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 5.2.0
Jul 18, 2023