Element Pack

Vendor:

First CVE: Mar 23, 2024 · Active for 2 years

34
Total CVEs
More Total CVEs than 96% of tracked products
17.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Element Pack over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2024
2 years ago
Most Recent CVE
Aug 6, 2025
352 days ago

CVE Severity & Scoring

Element Pack34 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network34 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (26.5%)
Unknown0 (0.0%)
Required25 (73.5%)
Privileges Required
Low32 (94.1%)
High0 (0.0%)
None2 (5.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Element
Mar 29, 20248.823NONO
The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content' parameter in versions up to, and includin
Aug 6, 20255.422NONO
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal,
Jun 4, 20246.520NONO
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sensitive Information Exposure in
Apr 11, 20247.520NONO
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in all versio
Aug 12, 20246.519NONO
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th
Jul 18, 20246.419NONO
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th
Jul 18, 20246.419NONO
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-caption’ attribute in all versions up to, and including, 8.0.0
Jul 3, 20255.418NONO
The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets
Apr 26, 20255.418NONO
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th
Nov 2, 20245.418NONO

Exploit Exposure

Signals from CVEs in this product scope (34 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (34 CVEs).

Media Mentions

Signals from CVEs in this product scope (34 CVEs).

Top CNAs Publishing CVEs For Element Pack

Top CWEs

Versions

No cataloged versions.