CVE-2026-40745
Element Pack – Widgets, Templates & Addons for Elementor
Minimum safe version
8.5.0
Update to 8.5.0 or later to address 41 fixable vulnerabilities
Element Pack Addons for Elementor <= 8.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Image Widget
Element Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary File Read
CVE-2025-31413
CVE-2025-13196
CVE-2025-11536
Element Pack Elementor Addons and Templates <= 8.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content
Element Pack Addons for Elementor <= 8.0.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute
Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.29 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.28 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
CVE-2024-12851
CVE-2024-11852
CVE-2024-9058
CVE-2024-10980
CVE-2024-10493
CVE-2024-9867
CVE-2024-9657
CVE-2024-9868
CVE-2024-10310
CVE-2024-47392
CVE-2024-7247
CVE-2024-4359
CVE-2024-4360
CVE-2024-39667
CVE-2024-4643
CVE-2024-5555
CVE-2024-5554
CVE-2024-3925
CVE-2024-3926
CVE-2024-3927
CVE-2024-32572
CVE-2024-1429
CVE-2024-1426
WordPress Element Pack Elementor Addons Plugin <= 5.5.6 is vulnerable to Sensitive Data Exposure
CVE-2024-1428
CVE-2024-0837
CVE-2024-30496
CVE-2024-30185
CVE-2024-24840
WordPress Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) Plugin <= 5.2.0 is vulnerable to Cross Site Scripting (XSS)