CVE-2026-40721: WordPress Element Pack Pro plugin <= 9.0.6 - Local File Inclusion vulnerability
Published Jun 17, 2026
·Updated
Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.
Affected Software
1 affected component
WPDeveloper Element Pack Pro<=9.0.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Element Pack Pro Pluginto a version that resolves this vulnerability.Fixed in 9.1.0
Event History
Jun 17, 2026
CVE Published
via MITRE·09:50 AM
Data Sourced
via MITRE·09:50 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-40721?
The severity of CVE-2026-40721 is high, rated at 7.5 on the CVSS scale.
2
How do I fix CVE-2026-40721?
To fix CVE-2026-40721, update the Element Pack Pro plugin to version 9.0.7 or later.
3
What type of vulnerability is CVE-2026-40721?
CVE-2026-40721 is a Local File Inclusion vulnerability affecting the Element Pack Pro plugin.
4
What versions of Element Pack Pro are affected by CVE-2026-40721?
CVE-2026-40721 affects Element Pack Pro versions 9.0.6 and earlier.
5
Who is affected by CVE-2026-40721?
Users of the WPDeveloper Element Pack Pro plugin versions 9.0.6 and below are affected by CVE-2026-40721.