SecAlerts
e

element pack

Security Risk Profile

28
/100
low

Security Risk Score

Comprehensive risk assessment based on 23 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 11, 2024 to present

23
Total CVEs
1
Critical+High
0
Exploited
1
Unpatched

Threat Assessment

Avg CVSS
6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
28/100
low

Severity Distribution

Critical
0
High
1
Medium
22
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
8

Age Distribution

Common Weaknesses (CWE)

1
XSS
17
2
SSRF
1
3
Infoleak
1

Most Affected Products

1. bdthemes Element Pack Wordpress18
2. Element Pack Elementor Addons14
3. Element Pack Element Pack Addons for Elementor5
4. Element Pack Elementor Addons and Templates1
5. Element Pack Element Pack Addons1

Recent Vulnerabilities

See more →
CVE-2026-65502
CVSS 5.3medium

WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vulnerability

Aug 6, 2026🔧 No Patch
CVE-2025-13196
CVSS 5.4medium

Element Pack Addons for Elementor <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map widget

Nov 18, 2025🔧 No Patch
CVE-2025-11536
CVSS 5.0medium

Element Pack Addons for Elementor <= 8.2.5 - Authenticated (Subscriber+) Blind Server-Side Request Forgery

Oct 20, 2025🔧 No Patch
CVE-2025-8100
CVSS 5.4EPSS 0%medium

Element Pack Elementor Addons and Templates <= 8.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content

Aug 6, 2025🔧 No Patch
CVE-2025-5944
CVSS 6.4EPSS 0%medium

Element Pack Addons for Elementor <= 8.0.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute

Jul 3, 2025
CVE-2025-5292
CVSS 6.4EPSS 0%medium

Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

May 31, 2025🔧 No Patch
CVE-2025-1458
CVSS 6.4medium

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.29 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 26, 2025
CVE-2025-1457
CVSS 6.4medium

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.28 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

Apr 19, 2025🔧 No Patch
CVE-2024-11852
CVSS 4.3medium

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.12 - Missing Authorization

Dec 22, 2024
CVE-2024-9058
CVSS 6.4EPSS 0%medium

Element Pack Elementor Addons <= 5.10.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Lightbox Widget

Dec 3, 2024

Monitor element pack in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.