Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40745

26
FAUCET Score

OVERVIEW CVE-2026-40745 is a Blind SQL Injection vulnerability in bdthemes Element Pack Elementor Addons, a WordPress plugin. The flaw stems from improper neutralization of special elements in SQL commands and affects versions up to and including 8.4.2. This vulnerability allows attackers to execute unauthorized SQL queries through the vulnerable plugin. SEVERITY The vulnerability carries a HIGH severity rating with a CVSS score of 7.6. The attack vector is network-based with low attack complexity, requiring high-level privileges but no user interaction. The impact is significant, providing attackers with high confidentiality impact through data extraction and low availability impact, with the ability to affect systems beyond the vulnerable component. EXPLOITATION STATUS Currently, there is no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and exploit code does not appear to be publicly available. The EPSS score of 0.00036 indicates minimal community attention and exploitation probability at present, though organizations running affected plugin versions should prioritize patching to version 8.4.3 or later.

Impacted Technologies

VendorProductVersion(s)CPE
BdthemesElement Pack Elementor Addons
>= 0, <= 8.4.2CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

7.6HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.3
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
14.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 1st percentile among its peer group of 5,538 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

patchstack.com / database/Wordpress/Plugin/bdthemes-element-pack-lite/vulnerability/wordpress-element-pack-elementor-addons-plugin-8-4-2-sql-injection-vulnerability