
Element Pack Addons for Elementor Security & Risk Analysis
wordpress.org/plugins/bdthemes-element-pack-liteUltimate Elementor addon with 300+ widgets, templates, live copy paste, post grid, header footer, mega menu, dynamic builder, WooCommerce and more.
Is Element Pack Addons for Elementor Safe to Use in 2026?
Generally Safe
Score 89/100Element Pack Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
This analysis of "bdthemes-element-pack-lite" v8.4.2 reveals a mixed security posture. While the plugin demonstrates good practices in output escaping (92%) and has a substantial number of capability checks (32), significant concerns arise from its attack surface and historical vulnerability patterns.
The plugin exposes a considerable number of entry points, with 14 out of 35 total entry points lacking authentication checks. This, coupled with a high percentage of unsanitized paths identified in taint analysis (9 out of 15 flows) and the presence of a critical severity taint flow, indicates a risk of unauthorized access and potential code execution. The use of the `unserialize` function is also a red flag, as it can lead to deserialization vulnerabilities if not handled with extreme care.
The plugin's vulnerability history is extensive, with 36 known CVEs, including one historical critical vulnerability. The common vulnerability types listed (Path Traversal, CSRF, XSS, SSRF, RFI, etc.) suggest recurring issues with input validation and authorization. While there are currently no unpatched CVEs, the sheer volume and variety of past vulnerabilities suggest a persistent need for rigorous security development practices. The last reported vulnerability in 2026-02-14 (assuming this is a typo and should be a past date) is concerning if it implies recent critical flaws.
In conclusion, while the plugin has strengths in output sanitization and capability checks, the significant number of unprotected entry points, identified taint flows, and a history of diverse and severe vulnerabilities present a substantial security risk. Users should exercise caution and ensure regular updates are applied, though the underlying codebase may require significant security hardening.
Key Concerns
- Unprotected AJAX handlers
- High percentage of unsanitized paths in taint analysis
- Critical severity taint flow
- Dangerous function: unserialize
- Significant historical CVEs (36 total)
- Historical critical CVE
- Common vulnerability types indicate recurring issues
- SQL queries with low prepared statement usage (70% not prepared)
Element Pack Addons for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
36 total CVEs
Element Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary File Read
Element Pack Elementor Addons <= 8.3.13 - Cross-Site Request Forgery
Element Pack Addons for Elementor <= 8.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map widget
Element Pack Addons for Elementor <= 8.2.5 - Authenticated (Subscriber+) Blind Server-Side Request Forgery
Element Pack Elementor Addons and Templates <= 8.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content
Element Pack Addons for Elementor <= 8.0.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-caption Attribute
Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.29 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.28 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Element Pack Lite - Addons for Elementor <= 5.10.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.12 - Missing Authorization
Element Pack Elementor Addons <= 5.10.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Lightbox Widget
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Cookie Consent'
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Open Map Widget
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate
Element Pack Elementor Addons <= 5.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 - Authenticated (Contributor+) Arbitrary File Read
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via onclick events
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.3 - Form Submission Admin Email Bypass
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via custom_attributes
Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget
Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.5.6 - Sensitive Information Exposure via element_pack_ajax_search
Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget
Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget
Element Pack Elementor Addons <= 5.5.3 - Authenticated (Contributor+) SQL Injection
Element Pack Elementor Addons <= 5.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via link
Element Pack Elementor Addons <= 5.4.11 - Missing Authorization via bdt_duplicate_as_draft
Element Pack Addons for Elementor Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Element Pack Addons for Elementor Attack Surface
AJAX Handlers 33
Shortcodes 2
WordPress Hooks 174
Maintenance & Trust
Element Pack Addons for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Element Pack Addons for Elementor Alternatives
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Royal Addons for Elementor – Addons and Templates Kit for Elementor
royal-elementor-addons
Elementor templates, Header footer builder, Elementor Post Grid, Woocommerce Grid builder, Slider, Forms, Gallery, Nav menu addons, Elementor widgets.
Unlimited Elements For Elementor
unlimited-elements-for-elementor
Elementor all-in-one addons pack with the best widgets for Elementor, offering 100+ free widgets, templates, and tools to create stunning websites!
Element Pack Addons for Elementor Developer Profile
24 plugins · 251K total installs
How We Detect Element Pack Addons for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bdthemes-element-pack-lite/assets/css/element-pack-lite.css/wp-content/plugins/bdthemes-element-pack-lite/assets/js/element-pack-lite.js/wp-content/plugins/bdthemes-element-pack-lite/assets/css/frontend.css/wp-content/plugins/bdthemes-element-pack-lite/assets/js/element-pack-lite.jsbdthemes-element-pack-lite/assets/css/element-pack-lite.css?ver=bdthemes-element-pack-lite/assets/js/element-pack-lite.js?ver=HTML / DOM Fingerprints
bdt-ep-element-buttonbdt-element-pack-editor<!-- element-pack -->data-bdt-element-packelement_pack_lite_params