Junglewise Threat Intelligence

CVE-2026-40721: BdThemes Element Pack Pro Local File Inclusion

CVE-2026-40721 · Severity: high · CVSS 7.5 · Published 2026-06-17

Vendors: BdThemes.

Executive brief

Element Pack Pro is a popular addon for the Elementor website builder on WordPress, providing additional design widgets and features. A security vulnerability in versions 9.0.6 and earlier allows users with 'Contributor' level access to view sensitive internal files on the web server. This could lead to the exposure of database credentials or other configuration secrets, potentially resulting in a full site takeover.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the BdThemes Element Pack Pro plugin for WordPress due to improper control of filenames in include or require statements (CWE-98). The flaw allows an authenticated attacker with Contributor-level privileges to manipulate file paths and include local files from the server's filesystem. While the attack complexity is rated as high, successful exploitation can lead to the disclosure of sensitive information such as the wp-config.php file, which contains database credentials. The issue is resolved in version 9.1.0.

Affected products

  • BdThemes Element Pack Pro <= 9.0.6

Timeline

  • 2025-12-15: other: Vulnerability reported by researcher Phat RiO
  • 2026-01-14: advisory: Patchstack published advisory and assigned priority
  • 2026-06-17: disclosed: CVE published to the National Vulnerability Database (NVD)
  • 2026-01-14: patched: Fixed in version 9.1.0

References