OVERVIEW CVE-2026-40745 is a Blind SQL Injection vulnerability in bdthemes Element Pack Elementor Addons, a WordPress plugin. The flaw stems from improper neutralization of special elements in SQL commands and affects versions up to and including 8.4.2. This vulnerability allows attackers to execute unauthorized SQL queries through the vulnerable plugin. SEVERITY The vulnerability carries a HIGH severity rating with a CVSS score of 7.6. The attack vector is network-based with low attack complexity, requiring high-level privileges but no user interaction. The impact is significant, providing attackers with high confidentiality impact through data extraction and low availability impact, with the ability to affect systems beyond the vulnerable component. EXPLOITATION STATUS Currently, there is no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and exploit code does not appear to be publicly available. The EPSS score of 0.00036 indicates minimal community attention and exploitation probability at present, though organizations running affected plugin versions should prioritize patching to version 8.4.3 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Bdthemes | Element Pack Elementor Addons | >= 0, <= 8.4.2CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.