CVE-2026-40745: WordPress Element Pack Elementor Addons plugin <= 8.4.2 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Blind SQL Injection.This issue affects Element Pack Elementor Addons: from n/a through <= 8.4.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40745?
CVE-2026-40745 is classified as a high severity SQL Injection vulnerability.
How do I fix CVE-2026-40745?
To fix CVE-2026-40745, update the bdthemes Element Pack Elementor Addons plugin to a version later than 8.4.2.
What impact does CVE-2026-40745 have on my website?
CVE-2026-40745 can allow attackers to execute arbitrary SQL queries, potentially compromising your website's database.
Is my site vulnerable if I am using a version of the Element Pack Elementor Addons plugin earlier than 8.4.3?
Yes, any version of the Element Pack Elementor Addons plugin up to and including 8.4.2 is vulnerable to CVE-2026-40745.
What are the signs of exploitation regarding CVE-2026-40745?
Signs of exploitation may include unusual database activity, unexpected data changes, or the presence of unauthorized SQL query logs.