cleantalk
Vulnerabilities and Security Researches

Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, , PSC-2026-64644

PSC, Research URL

PSC-2026-64644

Published on
Apr 16, 2026
Research Description
Elementor addon suites are security-relevant because they add a large amount of front-end rendering and stored widget configuration into WordPress. These plugins frequently process user-controlled strings (titles, labels, URLs, templates) and expose admin-side builders and settings that, if not defended correctly, can become paths to stored XSS, CSRF-driven configuration changes, privilege boundary issues, or information disclosure via misconfigured endpoints. Element Pack – Widgets, Templates & Addons for Elementor version 8.6.0 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64644, confirming that the plugin was reviewed from a secure code perspective with attention to the most common exploitation paths for Elementor widget and template libraries.
Affected versions
Min 8.6.0, max 8.6.0.
Status
SAFE & CERTIFIED