CVE-2025-46257: WordPress Element Pack Pro Plugin < 8.0.0 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a before 8.0.0.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro bdthemes-element-pack allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a through < 8.0.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46257?
CVE-2025-46257 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability, which can potentially lead to unauthorized actions on behalf of users.
How do I fix CVE-2025-46257?
To resolve CVE-2025-46257, update the BdThemes Element Pack Pro to a version above 8.0.0.
Who is affected by CVE-2025-46257?
CVE-2025-46257 affects users of BdThemes Element Pack Pro versions prior to 8.0.0.
What type of attack does CVE-2025-46257 enable?
CVE-2025-46257 allows attackers to perform Cross-Site Request Forgery (CSRF) attacks on vulnerable installations.
Is there a patch available for CVE-2025-46257?
Yes, a patch is available in the updated version of BdThemes Element Pack Pro, which addresses the CSRF vulnerability.