Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress Element Pack Pro wordpress plugin to the latest available version (at least 8.0.0).
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17011 | Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a before 8.0.0. |
Tue, 28 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 28 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro bdthemes-element-pack allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a through < 8.0.0. | Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a before 8.0.0. |
| References |
|
Thu, 23 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 23 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a before 8.0.0. | Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro bdthemes-element-pack allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a through < 8.0.0. |
| References |
|
Thu, 05 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Jun 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a before 8.0.0. | |
| Title | WordPress Element Pack Pro Plugin < 8.0.0 - Cross Site Request Forgery (CSRF) vulnerability | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:12:37.097Z
Reserved: 2025-04-22T09:21:51.395Z
Link: CVE-2025-46257
Updated: 2025-06-05T17:52:55.435Z
Status : Deferred
Published: 2025-06-05T18:15:21.753
Modified: 2026-04-28T19:32:10.907
Link: CVE-2025-46257
No data.
OpenCVE Enrichment
Updated: 2026-05-01T08:00:13Z
EUVD