Element Pack
Vendor:
First CVE: Mar 23, 2024 · Active for 2 years
34
Total CVEs
More Total CVEs than 96% of tracked products
17.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Element Pack over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 23, 2024
2 years ago
Most Recent CVE
Aug 6, 2025
352 days ago
CVE Severity & Scoring
Element Pack34 CVEs
94%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network34 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (26.5%)
Unknown0 (0.0%)
Required25 (73.5%)
Privileges Required
Low32 (94.1%)
High0 (0.0%)
None2 (5.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-30496HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Element | Mar 29, 2024 | 8.8 | 23 | NO | NO |
CVE-2025-8100MEDIUM The Element Pack Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content' parameter in versions up to, and includin | Aug 6, 2025 | 5.4 | 22 | NO | NO |
CVE-2024-33568MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal, | Jun 4, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-2966HIGH The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sensitive Information Exposure in | Apr 11, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-4359MEDIUM The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in all versio | Aug 12, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-5555MEDIUM The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th | Jul 18, 2024 | 6.4 | 19 | NO | NO |
CVE-2024-5554MEDIUM The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th | Jul 18, 2024 | 6.4 | 19 | NO | NO |
CVE-2025-5944MEDIUM The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-caption’ attribute in all versions up to, and including, 8.0.0 | Jul 3, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-1458MEDIUM The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets | Apr 26, 2025 | 5.4 | 18 | NO | NO |
CVE-2024-9868MEDIUM The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th | Nov 2, 2024 | 5.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (34 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (34 CVEs).
Media Mentions
Signals from CVEs in this product scope (34 CVEs).
Top CNAs Publishing CVEs For Element Pack
Top CWEs
Versions
No cataloged versions.