SQL Injection Vulnerability in bdthemes Element Pack for Elementor Plugins
CVE-2026-40745

7.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 April 2026

What is CVE-2026-40745?

The bdthemes Element Pack Elementor Addons plugin has a vulnerability due to improper handling of special elements in SQL commands, leading to potential blind SQL injection attacks. This flaw can allow attackers to manipulate database queries, posing a risk to data integrity and application security. Affected versions include bdthemes-element-pack-lite up to 8.4.2. It is crucial for users to update to patched versions to mitigate this vulnerability.

Affected Version(s)

Element Pack Elementor Addons 0 <= 8.4.2

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.