Biggopti Library (Various Versions) - Cross-Site Scripting via display_id from Sigmative API
medium
The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for attackers who can compromise the Sigmative API server to inject arbitrary web scripts in pages that will execute whenever a u...
- CVSS:
- 5.4
- Affected:
- up to 8.7.14
- Fixed in:
- 8.7.15
- Disclosed:
- Aug 8, 2026
Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Injection
medium
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the `element_pack_contact_form` AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email headers...
- CVSS:
- 5.3
- Affected:
- up to 8.3.15
- Fixed in:
- 8.3.16
- Disclosed:
- Aug 6, 2026
CVE-2026-0673 on NVD →
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons < 8.7.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 8.7.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-lev...
- CVSS:
- 6.4
- Affected:
- up to 8.7.13
- Fixed in:
- 8.7.13
- Disclosed:
- Aug 2, 2026
CVE-2026-14817 on NVD →
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons <= 8.7.13 - Missing Authorization
medium
The Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 8.7.13. This makes it possible for unauthenticated attackers to perform an unau...
- CVSS:
- 5.3
- Affected:
- up to 8.7.13
- Fixed in:
- 8.7.14
- Disclosed:
- Jul 28, 2026
CVE-2026-65502 on NVD →
Element Pack Addons for Elementor <= 8.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Image Widget
medium
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Image Widget in versions up to and including 8.4.2. This is due to insufficient input sanitization and output escaping on SVG content fetched from remote URLs in the render_svg() function. The function fe...
- CVSS:
- 6.4
- Affected:
- up to 8.4.2
- Fixed in:
- 8.5.0
- Disclosed:
- Apr 7, 2026
CVE-2026-4655 on NVD →
Element Pack Elementor Addons <= 8.4.2 - Authenticated (Editor+) SQL Injection
medium
The Element Pack Elementor Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level ac...
- CVSS:
- 4.9
- Affected:
- up to 8.4.2
- Fixed in:
- 8.5.0
- Disclosed:
- Mar 23, 2026
CVE-2026-40745 on NVD →
Element Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary File Read
medium
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the SVG widget and a lack of sufficient file validation in the 'render_svg' function. This makes it possible for authenticated attackers, with contributor-level access and ab...
- CVSS:
- 6.5
- Affected:
- up to 8.3.17
- Fixed in:
- 8.3.18
- Disclosed:
- Feb 14, 2026
CVE-2026-1793 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] <= 8.3.13 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Cross Site Request Forgery.This issue affects Element Pack Elementor Addons: from n/a through <= 8.3.13.
- Affected:
- up to 8.3.13
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-31413 on NVD →
Element Pack Elementor Addons <= 8.3.13 - Cross-Site Request Forgery
medium
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.13. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can...
- CVSS:
- 4.3
- Affected:
- up to 8.3.13
- Fixed in:
- 8.3.14
- Disclosed:
- Jan 16, 2026
CVE-2025-31413 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 8.3.5
unknown
[en] The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Street Map widget's marker content parameter in all versions up to, and including, 8.3.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the render...
- Affected:
- up to 8.3.5
- Fixed in:
- 8.3.5
- Disclosed:
- Nov 18, 2025
CVE-2025-13196 on NVD →
Element Pack Addons for Elementor <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map widget
medium
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Street Map widget's marker content parameter in all versions up to, and including, 8.3.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the render func...
- CVSS:
- 5.4
- Affected:
- up to 8.3.4
- Fixed in:
- 8.3.5
- Disclosed:
- Nov 17, 2025
CVE-2025-13196 on NVD →
Element Pack Addons for Elementor <= 8.2.5 - Authenticated (Subscriber+) Blind Server-Side Request Forgery
medium
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8.2.5 via the wp_ajax_import_elementor_template action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to...
- CVSS:
- 5
- Affected:
- up to 8.2.5
- Fixed in:
- 8.2.6
- Disclosed:
- Oct 20, 2025
CVE-2025-11536 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 8.2.6
unknown
[en] The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8.2.5 via the wp_ajax_import_elementor_template action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web request...
- Affected:
- up to 8.2.6
- Fixed in:
- 8.2.6
- Disclosed:
- Oct 20, 2025
CVE-2025-11536 on NVD →
Element Pack Elementor Addons and Templates <= 8.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content
medium
The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content' parameter in versions up to, and including, 8.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-le...
- CVSS:
- 5.4
- Affected:
- up to 8.1.5
- Fixed in:
- 8.1.6
- Disclosed:
- Aug 5, 2025
CVE-2025-8100 on NVD →
Element Pack Addons for Elementor <= 8.0.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute
medium
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-caption’ attribute in all versions up to, and including, 8.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acce...
- CVSS:
- 6.4
- Affected:
- 8.0.0 – 8.0.0
- Fixed in:
- 8.1.0
- Disclosed:
- Jul 2, 2025
CVE-2025-5944 on NVD →
Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content’ parameter in all versions up to, and including, 5.11.2 due to insufficient input sanitization and output...
- CVSS:
- 6.4
- Affected:
- up to 5.11.2
- Fixed in:
- 5.11.3
- Disclosed:
- May 30, 2025
CVE-2025-5292 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.29 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like Dual Button, Creative Button, Image Stack and more in all versions up to, and including, 5.10.29 due to insufficient input sanitizatio...
- CVSS:
- 6.4
- Affected:
- up to 5.10.29
- Fixed in:
- 5.10.30
- Disclosed:
- Apr 25, 2025
CVE-2025-1458 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.28 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Wrapper Link, Countdown and Gallery widgets in all versions up to, and including, 5.10.28 due to insufficient input sanitization and output escaping. T...
- CVSS:
- 6.4
- Affected:
- up to 5.10.28
- Fixed in:
- 5.10.29
- Disclosed:
- Apr 18, 2025
CVE-2025-1457 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.10.15
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes parameter of the Cookie Consent Widget in all versions up to, and including, 5.10.14 due to insufficient input sa...
- Affected:
- up to 5.10.15
- Fixed in:
- 5.10.15
- Disclosed:
- Jan 8, 2025
CVE-2024-12851 on NVD →
Element Pack Lite - Addons for Elementor <= 5.10.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes parameter of the Cookie Consent Widget in all versions up to, and including, 5.10.14 due to insufficient input sanitiz...
- CVSS:
- 6.4
- Affected:
- up to 5.10.14
- Fixed in:
- 5.10.15
- Disclosed:
- Jan 7, 2025
CVE-2024-12851 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.12 - Missing Authorization
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_layouts() function in all versions up to, and including, 5.10.12. This makes it possible for authen...
- CVSS:
- 4.3
- Affected:
- up to 5.10.12
- Fixed in:
- 5.10.13
- Disclosed:
- Dec 21, 2024
CVE-2024-11852 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.10.6
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lightbox widget in all versions up to, and including, 5.10.5 due to insufficient input sanitization and output escaping. This makes i...
- Affected:
- up to 5.10.6
- Fixed in:
- 5.10.6
- Disclosed:
- Dec 3, 2024
CVE-2024-9058 on NVD →
Element Pack Elementor Addons <= 5.10.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Lightbox Widget
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lightbox widget in all versions up to, and including, 5.10.5 due to insufficient input sanitization and output escaping. This makes it pos...
- CVSS:
- 6.4
- Affected:
- up to 5.10.5
- Fixed in:
- 5.10.6
- Disclosed:
- Dec 2, 2024
CVE-2024-9058 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.10.3
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the co...
- Affected:
- up to 5.10.3
- Fixed in:
- 5.10.3
- Disclosed:
- Nov 29, 2024
CVE-2024-10980 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.10.3
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role an...
- Affected:
- up to 5.10.3
- Fixed in:
- 5.10.3
- Disclosed:
- Nov 28, 2024
CVE-2024-10493 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Cookie Consent'
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Cookie Consent block in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes...
- CVSS:
- 6.4
- Affected:
- up to 5.10.2
- Fixed in:
- 5.10.3
- Disclosed:
- Nov 14, 2024
CVE-2024-10980 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Lightbox' block in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it...
- CVSS:
- 6.4
- Affected:
- up to 5.10.2
- Fixed in:
- 5.10.3
- Disclosed:
- Nov 7, 2024
CVE-2024-10493 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.10.3
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip' parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This mak...
- Affected:
- up to 5.10.3
- Fixed in:
- 5.10.3
- Disclosed:
- Nov 5, 2024
CVE-2024-9657 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.10.3
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Open Map Widget' marker_content parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and ou...
- Affected:
- up to 5.10.3
- Fixed in:
- 5.10.3
- Disclosed:
- Nov 5, 2024
CVE-2024-9867 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip' parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it...
- CVSS:
- 6.5
- Affected:
- up to 5.10.2
- Fixed in:
- 5.10.3
- Disclosed:
- Nov 4, 2024
CVE-2024-9657 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Map Widget
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Open Map Widget' marker_content parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output...
- CVSS:
- 5.4
- Affected:
- up to 5.10.2
- Fixed in:
- 5.10.3
- Disclosed:
- Nov 4, 2024
CVE-2024-9867 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.10.2
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate Widget 'url' parameter in all versions up to, and including, 5.10.1 due to insufficient input sanitization and output escapi...
- Affected:
- up to 5.10.2
- Fixed in:
- 5.10.2
- Disclosed:
- Nov 2, 2024
CVE-2024-9868 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.10.2
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Gallery Widget 'image_title' parameter in all versions up to, and including, 5.10.1 due to insufficient input sanitization and...
- Affected:
- up to 5.10.2
- Fixed in:
- 5.10.2
- Disclosed:
- Nov 2, 2024
CVE-2024-10310 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Gallery Widget 'image_title' parameter in all versions up to, and including, 5.10.1 due to insufficient input sanitization and outp...
- CVSS:
- 6.4
- Affected:
- up to 5.10.1
- Fixed in:
- 5.10.2
- Disclosed:
- Nov 1, 2024
CVE-2024-10310 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate Widget 'url' parameter in all versions up to, and including, 5.10.1 due to insufficient input sanitization and output escaping. T...
- CVSS:
- 5.4
- Affected:
- up to 5.10.1
- Fixed in:
- 5.10.2
- Disclosed:
- Nov 1, 2024
CVE-2024-9868 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.7.6
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 5.7.5.
- Affected:
- up to 5.7.6
- Fixed in:
- 5.7.6
- Disclosed:
- Oct 5, 2024
CVE-2024-47392 on NVD →
Element Pack Elementor Addons <= 5.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Element Pack Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 5.7.5
- Fixed in:
- 5.7.6
- Disclosed:
- Sep 30, 2024
CVE-2024-47392 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.7.3
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Gallery and Countdown widgets in all versions up to, and including, 5.7.2 due to insufficient input sanitization and...
- Affected:
- up to 5.7.3
- Fixed in:
- 5.7.3
- Disclosed:
- Aug 13, 2024
CVE-2024-7247 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Gallery and Countdown widgets in all versions up to, and including, 5.7.2 due to insufficient input sanitization and outpu...
- CVSS:
- 6.4
- Affected:
- up to 5.7.2
- Fixed in:
- 5.7.3
- Disclosed:
- Aug 12, 2024
CVE-2024-7247 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.7.7
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user suppl...
- Affected:
- up to 5.7.7
- Fixed in:
- 5.7.7
- Disclosed:
- Aug 9, 2024
CVE-2024-4360 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.7.3
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 5.7.2 via the SVG widget and a lack of sufficient file validation in the render_svg function. This makes it po...
- Affected:
- up to 5.7.3
- Fixed in:
- 5.7.3
- Disclosed:
- Aug 9, 2024
CVE-2024-4359 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 - Authenticated (Contributor+) Arbitrary File Read
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 5.7.2 via the SVG widget and a lack of sufficient file validation in the render_svg function. This makes it possibl...
- CVSS:
- 6.5
- Affected:
- up to 5.7.2
- Fixed in:
- 5.7.3
- Disclosed:
- Aug 8, 2024
CVE-2024-4359 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 5.7.6 due to insufficient input sanitization and output escaping on user supplied a...
- CVSS:
- 6.4
- Affected:
- up to 5.7.6
- Fixed in:
- 5.7.7
- Disclosed:
- Aug 8, 2024
CVE-2024-4360 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.6.12
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘end_redirect_link’ parameter in versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. Thi...
- Affected:
- up to 5.6.12
- Fixed in:
- 5.6.12
- Disclosed:
- Aug 2, 2024
CVE-2024-4643 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘end_redirect_link’ parameter in versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This mak...
- CVSS:
- 6.4
- Affected:
- up to 5.6.11
- Fixed in:
- 5.6.12
- Disclosed:
- Aug 1, 2024
CVE-2024-4643 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.6.12
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 5.6.11.
- Affected:
- up to 5.6.12
- Fixed in:
- 5.6.12
- Disclosed:
- Aug 1, 2024
CVE-2024-39667 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.6.12
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘onclick_event’ parameter in all versions up to, and including, 5.6.11 due to insufficient input sanitization and output escaping. Th...
- Affected:
- up to 5.6.12
- Fixed in:
- 5.6.12
- Disclosed:
- Jul 18, 2024
CVE-2024-5554 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.6.6
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘social-link-title’ parameter in all versions up to, and including, 5.6.5 due to insufficient input sanitization and output escaping....
- Affected:
- up to 5.6.6
- Fixed in:
- 5.6.6
- Disclosed:
- Jul 18, 2024
CVE-2024-5555 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘social-link-title’ parameter in all versions up to, and including, 5.6.5 due to insufficient input sanitization and output escaping. This...
- CVSS:
- 6.4
- Affected:
- up to 5.6.5
- Fixed in:
- 5.6.6
- Disclosed:
- Jul 17, 2024
CVE-2024-5555 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘onclick_event’ parameter in all versions up to, and including, 5.6.11 due to insufficient input sanitization and output escaping. This ma...
- CVSS:
- 6.4
- Affected:
- up to 5.6.11
- Fixed in:
- 5.6.12
- Disclosed:
- Jul 17, 2024
CVE-2024-5554 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.6.12
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, and including, 5.6.7 due to insufficient input sanitization and output escapin...
- Affected:
- up to 5.6.12
- Fixed in:
- 5.6.12
- Disclosed:
- Jun 12, 2024
CVE-2024-3925 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via onclick events
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, and including, 5.6.11 due to insufficient input sanitization and output escaping on...
- CVSS:
- 6.4
- Affected:
- up to 5.6.11
- Fixed in:
- 5.6.12
- Disclosed:
- Jun 11, 2024
CVE-2024-3925 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.6.4
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to the plugin not properly checking for all variations of an administrators...
- Affected:
- up to 5.6.4
- Fixed in:
- 5.6.4
- Disclosed:
- May 22, 2024
CVE-2024-3927 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.6.2
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes value in widgets in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output esca...
- Affected:
- up to 5.6.2
- Fixed in:
- 5.6.2
- Disclosed:
- May 22, 2024
CVE-2024-3926 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via custom_attributes
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes value in widgets in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping...
- CVSS:
- 6.4
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.2
- Disclosed:
- May 21, 2024
CVE-2024-3926 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.3 - Form Submission Admin Email Bypass
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to the plugin not properly checking for all variations of an administrators email...
- CVSS:
- 5.3
- Affected:
- up to 5.6.3
- Fixed in:
- 5.6.4
- Disclosed:
- May 21, 2024
CVE-2024-3927 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.6.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 5.6.0.
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.1
- Disclosed:
- Apr 18, 2024
CVE-2024-32572 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.6.1
unknown
[en] The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ attribute of the Price List widget in all versions up to, and including, 5.6.0 due to ins...
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.1
- Disclosed:
- Apr 18, 2024
CVE-2024-1426 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.6.1
unknown
[en] The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tab_link’ attribute of the Panel Slider widget in all versions up to, and including, 5.6.0 due...
- Affected:
- up to 5.6.1
- Fixed in:
- 5.6.1
- Disclosed:
- Apr 18, 2024
CVE-2024-1429 on NVD →
Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget
medium
The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tab_link’ attribute of the Panel Slider widget in all versions up to, and including, 5.6.0 due to in...
- CVSS:
- 6.4
- Affected:
- up to 5.6.0
- Fixed in:
- 5.6.1
- Disclosed:
- Apr 17, 2024
CVE-2024-1429 on NVD →
Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget
medium
The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ attribute of the Price List widget in all versions up to, and including, 5.6.0 due to insuffic...
- CVSS:
- 6.4
- Affected:
- up to 5.6.0
- Fixed in:
- 5.6.1
- Disclosed:
- Apr 17, 2024
CVE-2024-1426 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.6.0
unknown
[en] The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.5.6 via the element_pack_ajax_search function. This makes it possible for unauthenticated attacke...
- Affected:
- up to 5.6.0
- Fixed in:
- 5.6.0
- Disclosed:
- Apr 11, 2024
CVE-2024-2966 on NVD →
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.5.6 - Sensitive Information Exposure via element_pack_ajax_search
medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.5.6 via the element_pack_ajax_search function. This makes it possible for unauthenticated attackers to...
- CVSS:
- 5.3
- Affected:
- up to 5.5.6
- Fixed in:
- 5.6.0
- Disclosed:
- Apr 10, 2024
CVE-2024-2966 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.5.4
unknown
[en] The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘element_pack_wrapper_link’ attribute of the Trailer Box widget in all versions up to, and inclu...
- Affected:
- up to 5.5.4
- Fixed in:
- 5.5.4
- Disclosed:
- Apr 6, 2024
CVE-2024-1428 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.3.3
unknown
[en] The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image URL parameter in all versions up to, and including, 5.3.2 due to insufficient input saniti...
- Affected:
- up to 5.3.3
- Fixed in:
- 5.3.3
- Disclosed:
- Apr 6, 2024
CVE-2024-0837 on NVD →
Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget
medium
The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘element_pack_wrapper_link’ attribute of the Trailer Box widget in all versions up to, and including,...
- CVSS:
- 6.4
- Affected:
- up to 5.5.3
- Fixed in:
- 5.5.4
- Disclosed:
- Apr 5, 2024
CVE-2024-1428 on NVD →
Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget
medium
The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image URL parameter in all versions up to, and including, 5.3.2 due to insufficient input sanitizatio...
- CVSS:
- 6.4
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.3
- Disclosed:
- Apr 5, 2024
CVE-2024-0837 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.5.4
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.5.3.
- Affected:
- up to 5.5.4
- Fixed in:
- 5.5.4
- Disclosed:
- Mar 29, 2024
CVE-2024-30496 on NVD →
Element Pack Elementor Addons <= 5.5.3 - Authenticated (Contributor+) SQL Injection
critical
The Element Pack Elementor Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-le...
- CVSS:
- 9.9
- Affected:
- up to 5.5.3
- Fixed in:
- 5.5.4
- Disclosed:
- Mar 28, 2024
CVE-2024-30496 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.5.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 5.5.3.
- Affected:
- up to 5.5.4
- Fixed in:
- 5.5.4
- Disclosed:
- Mar 27, 2024
CVE-2024-30185 on NVD →
Element Pack Elementor Addons <= 5.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via link
medium
The Element Pack Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link URL in versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject...
- CVSS:
- 6.4
- Affected:
- up to 5.5.3
- Fixed in:
- 5.5.4
- Disclosed:
- Mar 25, 2024
CVE-2024-30185 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.4.12
unknown
[en] Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.4.11.
- Affected:
- up to 5.4.12
- Fixed in:
- 5.4.12
- Disclosed:
- Mar 23, 2024
CVE-2024-24840 on NVD →
Element Pack Elementor Addons <= 5.4.11 - Missing Authorization via bdt_duplicate_as_draft
medium
The Element Pack Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'bdt_duplicate_as_draft' function in versions up to, and including, 5.4.11. This makes it possible for authenticated attackers, with contributor-level access and above, to d...
- CVSS:
- 4.3
- Affected:
- up to 5.4.11
- Fixed in:
- 5.4.12
- Disclosed:
- Feb 2, 2024
CVE-2024-24840 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 8.1.0
unknown
- Affected:
- up to 8.1.0
- Fixed in:
- 8.1.0
CVE-2025-5944 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 8.1.6
unknown
- Affected:
- up to 8.1.6
- Fixed in:
- 8.1.6
CVE-2025-8100 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.2.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 5.2.1
- Fixed in:
- 5.2.1
CVE-2023-33999 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.11.3
unknown
- Affected:
- up to 5.11.3
- Fixed in:
- 5.11.3
CVE-2025-5292 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.10.30
unknown
- Affected:
- up to 5.10.30
- Fixed in:
- 5.10.30
CVE-2025-1458 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.10.29
unknown
- Affected:
- up to 5.10.29
- Fixed in:
- 5.10.29
CVE-2025-1457 on NVD →
Element Pack Addons for Elementor [bdthemes-element-pack-lite] < 5.10.13
unknown
- Affected:
- up to 5.10.13
- Fixed in:
- 5.10.13
CVE-2024-11852 on NVD →