
Element Pack – Widgets, Templates & Addons for Elementor Security & Risk Analysis
wordpress.org/plugins/bdthemes-element-pack-liteElementor addons with 300+ widgets, templates, WooCommerce widgets, mega menu, header footer builder, and powerful design extensions.
Is Element Pack – Widgets, Templates & Addons for Elementor Safe to Use in 2026?
Generally Safe
Score 89/100Element Pack – Widgets, Templates & Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
This analysis of "bdthemes-element-pack-lite" v8.4.2 reveals a mixed security posture. While the plugin demonstrates good practices in output escaping (92%) and has a substantial number of capability checks (32), significant concerns arise from its attack surface and historical vulnerability patterns.
The plugin exposes a considerable number of entry points, with 14 out of 35 total entry points lacking authentication checks. This, coupled with a high percentage of unsanitized paths identified in taint analysis (9 out of 15 flows) and the presence of a critical severity taint flow, indicates a risk of unauthorized access and potential code execution. The use of the `unserialize` function is also a red flag, as it can lead to deserialization vulnerabilities if not handled with extreme care.
The plugin's vulnerability history is extensive, with 36 known CVEs, including one historical critical vulnerability. The common vulnerability types listed (Path Traversal, CSRF, XSS, SSRF, RFI, etc.) suggest recurring issues with input validation and authorization. While there are currently no unpatched CVEs, the sheer volume and variety of past vulnerabilities suggest a persistent need for rigorous security development practices. The last reported vulnerability in 2026-02-14 (assuming this is a typo and should be a past date) is concerning if it implies recent critical flaws.
In conclusion, while the plugin has strengths in output sanitization and capability checks, the significant number of unprotected entry points, identified taint flows, and a history of diverse and severe vulnerabilities present a substantial security risk. Users should exercise caution and ensure regular updates are applied, though the underlying codebase may require significant security hardening.
Key Concerns
- Unprotected AJAX handlers
- High percentage of unsanitized paths in taint analysis
- Critical severity taint flow
- Dangerous function: unserialize
- Significant historical CVEs (36 total)
- Historical critical CVE
- Common vulnerability types indicate recurring issues
- SQL queries with low prepared statement usage (70% not prepared)
Element Pack – Widgets, Templates & Addons for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
38 total CVEs
Element Pack Addons for Elementor <= 8.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Image Widget
Element Pack Elementor Addons <= 8.4.2 - Authenticated (Editor+) SQL Injection
Element Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary File Read
Element Pack Elementor Addons <= 8.3.13 - Cross-Site Request Forgery
Element Pack Addons for Elementor <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map widget
Element Pack Addons for Elementor <= 8.2.5 - Authenticated (Subscriber+) Blind Server-Side Request Forgery
Element Pack Elementor Addons and Templates <= 8.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content
Element Pack Addons for Elementor <= 8.0.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute
Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.29 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.28 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Element Pack Lite - Addons for Elementor <= 5.10.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.12 - Missing Authorization
Element Pack Elementor Addons <= 5.10.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Lightbox Widget
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Cookie Consent'
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Map Widget
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate
Element Pack Elementor Addons <= 5.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 - Authenticated (Contributor+) Arbitrary File Read
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via onclick events
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.3 - Form Submission Admin Email Bypass
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via custom_attributes
Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget
Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.5.6 - Sensitive Information Exposure via element_pack_ajax_search
Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget
Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget
Element Pack Elementor Addons <= 5.5.3 - Authenticated (Contributor+) SQL Injection
Element Pack Elementor Addons <= 5.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via link
Element Pack Elementor Addons <= 5.4.11 - Missing Authorization via bdt_duplicate_as_draft
Element Pack – Widgets, Templates & Addons for Elementor Release Timeline
Element Pack – Widgets, Templates & Addons for Elementor Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Element Pack – Widgets, Templates & Addons for Elementor Attack Surface
AJAX Handlers 33
Shortcodes 2
WordPress Hooks 174
Maintenance & Trust
Element Pack – Widgets, Templates & Addons for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Element Pack – Widgets, Templates & Addons for Elementor Alternatives
Unlimited Elements For Elementor
unlimited-elements-for-elementor
Elementor all-in-one addons pack with the best widgets for Elementor, offering 100+ free widgets, templates, and tools to create stunning websites!
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
the-plus-addons-for-elementor-page-builder
Best Addons for Elementor with 120+ Elementor FREE & Pro Widgets & 1000+ Elementor Templates with Mega Menu, Post Grid, Header Footer, WooCommerce
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits
master-addons
55+ Elementor widgets, 20+ extensions, Theme Builder, Popup Builder, Widget Builder & Template Kits — build any site without code.
King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder
king-addons
Elementor addons: Elementor widgets, Elementor templates, 80+ widgets, 4 000+ templates and sections, Mega Menu, Popup Builder, WooCommerce, AI tools.
Anant Addons for Elementor – Widgets, Templates & WooCommerce Builder
anant-addons-for-elementor
Extend Elementor with 80+ lightweight widgets, WooCommerce builder elements, header & footer builder, blog layouts, sliders, and ready-made Elemen …
Element Pack – Widgets, Templates & Addons for Elementor Developer Profile
24 plugins · 250K total installs
How We Detect Element Pack – Widgets, Templates & Addons for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bdthemes-element-pack-lite/assets/css/element-pack-lite.css/wp-content/plugins/bdthemes-element-pack-lite/assets/js/element-pack-lite.js/wp-content/plugins/bdthemes-element-pack-lite/assets/css/frontend.css/wp-content/plugins/bdthemes-element-pack-lite/assets/js/element-pack-lite.jsbdthemes-element-pack-lite/assets/css/element-pack-lite.css?ver=bdthemes-element-pack-lite/assets/js/element-pack-lite.js?ver=HTML / DOM Fingerprints
bdt-ep-element-buttonbdt-element-pack-editor<!-- element-pack -->data-bdt-element-packelement_pack_lite_params