Description
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the SVG widget and a lack of sufficient file validation in the 'render_svg' function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Published: 2026-02-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Read
Action: Patch
AI Analysis

Impact

The Element Pack Addons for Elementor plugin for WordPress allows an authenticated attacker with contributor-level access to read any file on the server via the SVG widget. The vulnerability stems from insufficient file validation in the 'render_svg' function, enabling read operations with arbitrary file paths. Successful exploitation could expose sensitive files such as configuration, credentials, or private data, compromising confidentiality and potentially facilitating further attacks.

Affected Systems

The flaw affects all releases of the bdthemes Element Pack – Widgets, Templates & Addons for Elementor plugin up to and including version 8.3.17. Any WordPress installation deploying these plugin versions is at risk, regardless of the site's public exposure. The affected components are the SVG widget and its internal file handling logic.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, implying it has not been observed in the wild or linked to known exploit kits. Because the attack requires authenticated contributor or higher permissions, the risk is primarily internal, relying on compromised user credentials or weak role assignments. While the potential impact includes unauthorized data exposure, the overall threat landscape remains moderate without an active exploit available.

Generated by OpenCVE AI on April 15, 2026 at 18:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Element Pack to a version newer than 8.3.17, or apply any vendor‑issued patch that addresses the 'render_svg' validation issue
  • If the SVG widget is not needed for site functionality, disable it entirely to eliminate the attack surface
  • Audit and adjust file system permissions so that the web server process can read only the files required for normal operation, reducing the risk of sensitive data exposure
  • Review and tighten WordPress user role assignments, ensuring contributor accounts have no unnecessary file‑read or editor capabilities

Generated by OpenCVE AI on April 15, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 17 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Bdthemes
Bdthemes element Pack Addons For Elementor
Wordpress
Wordpress wordpress
Vendors & Products Bdthemes
Bdthemes element Pack Addons For Elementor
Wordpress
Wordpress wordpress

Sun, 15 Feb 2026 04:15:00 +0000

Type Values Removed Values Added
Description The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 8.3.17 via the SVG widget and a lack of sufficient file validation in the 'render_svg' function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Title Element Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary File Read
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Bdthemes Element Pack Addons For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:54:39.864Z

Reserved: 2026-02-03T08:23:17.991Z

Link: CVE-2026-1793

cve-icon Vulnrichment

Updated: 2026-02-17T21:16:18.444Z

cve-icon NVD

Status : Deferred

Published: 2026-02-15T04:15:54.260

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-1793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T18:30:10Z

Weaknesses