Absolute Addons For Elementor Security & Risk Analysis

wordpress.org/plugins/absolute-addons

Absolute Addons For Elementor page builder is the best free Elementor addons comes with 17+ free Elementor Widgets including Advance Tab, Call to Acti …

400 active installs v1.0.14 PHP 7.1+ WP 5.2+ Updated Jul 13, 2022
elementorelementor-addonselementor-widgetelementsessential-elementor-widgets
38
D · High Risk
CVEs total2
Unpatched2
Last CVEJan 5, 2026
Safety Verdict

Is Absolute Addons For Elementor Safe to Use in 2026?

High Risk

Score 38/100

Absolute Addons For Elementor carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

2 known CVEs 2 unpatched Last CVE: Jan 5, 2026Updated 3yr ago
Risk Assessment

The "absolute-addons" plugin version 1.0.14 exhibits a mixed security posture. On the positive side, the static analysis reveals excellent practices regarding SQL query security, with 100% utilizing prepared statements. The plugin also demonstrates strong output escaping, with 97% of outputs properly handled, and a significant number of nonce and capability checks are in place. The absence of direct file operations and a clean taint analysis with no unsanitized paths are also commendable. However, a critical concern arises from the plugin's vulnerability history. The presence of two known CVEs, both of which are currently unpatched, with one being high severity and another medium severity, indicates a significant and persistent security risk. The common vulnerability types associated with past issues, specifically Missing Authorization and Remote File Inclusion, are particularly concerning as they can lead to severe compromises.

While the current code analysis shows a lack of immediate exploitable vulnerabilities (e.g., no unprotected entry points, no critical taint flows), the historical pattern of unpatched vulnerabilities cannot be overlooked. This suggests a potential for similar weaknesses to exist or to be reintroduced. The six AJAX handlers, although currently protected by authorization checks, represent potential points of entry that, if a future vulnerability were introduced, could be exploited. The external HTTP requests also warrant attention, as they can be a vector for introducing malicious code or data if not handled with extreme care. Therefore, while the code's immediate static analysis is largely positive, the unpatched historical vulnerabilities significantly elevate the risk profile of this plugin.

Key Concerns

  • Unpatched High Severity CVE
  • Unpatched Medium Severity CVE
Vulnerabilities
2

Absolute Addons For Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2026-22468medium · 4.3Missing Authorization

Absolute Addons For Elementor <= 1.0.14 - Missing Authorization

Jan 5, 2026Unpatched
CVE-2024-52496high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Absolute Addons For Elementor <= 1.0.14 - Authenticated (Contributor+) Local File Inclusion

Nov 20, 2024Unpatched
Code Analysis
Analyzed Mar 16, 2026

Absolute Addons For Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
34
1270 escaped
Nonce Checks
10
Capability Checks
7
File Operations
0
External Requests
6
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

97% escaped1304 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<class-insights> (includes\absolute-plugins-services\class-insights.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Absolute Addons For Elementor Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_absp_srv_dismiss_promoincludes\absolute-plugins-services\class-promotions.php:106
authwp_ajax_absp_post_like_actionincludes\ajax-handler.php:81
authwp_ajax_absp-mailchimp-subscribeincludes\ajax-handler.php:82
noprivwp_ajax_absp-mailchimp-subscribeincludes\ajax-handler.php:83
authwp_ajax_absp_save_widgetsincludes\settings\class-dashboard.php:80
authwp_ajax_absp_save_integrationsincludes\settings\class-dashboard.php:81
WordPress Hooks 81
actioninitclass-absolute-addons.php:105
actioninitclass-absolute-addons.php:108
actionplugins_loadedclass-absolute-addons.php:111
actionelementor/elements/categories_registeredclass-absolute-addons.php:113
actionadmin_noticesclass-absolute-addons.php:207
actionadmin_noticesclass-absolute-addons.php:214
actionadmin_noticesclass-absolute-addons.php:221
filterelementor/fonts/groupsclass-plugin.php:86
filterelementor/fonts/additional_fontsclass-plugin.php:89
actionwp_enqueue_scriptsclass-plugin.php:104
actionwp_enqueue_scriptsclass-plugin.php:107
actionelementor/preview/enqueue_stylesclass-plugin.php:109
actionelementor/editor/after_enqueue_scriptsclass-plugin.php:110
actionelementor/editor/after_enqueue_stylesclass-plugin.php:111
actionelementor/editor/after_enqueue_scriptsclass-plugin.php:112
actionelementor/controls/registerclass-plugin.php:118
actionelementor/widgets/registerclass-plugin.php:121
actionswitch_themeincludes\absolute-plugins-services\class-insights.php:210
actionswitch_themeincludes\absolute-plugins-services\class-insights.php:211
actionadmin_footerincludes\absolute-plugins-services\class-insights.php:223
actionadmin_noticesincludes\absolute-plugins-services\class-insights.php:242
actionadmin_initincludes\absolute-plugins-services\class-insights.php:245
actionremovable_query_argsincludes\absolute-plugins-services\class-insights.php:246
filtercron_schedulesincludes\absolute-plugins-services\class-insights.php:251
actioninitincludes\absolute-plugins-services\class-license.php:211
actionadmin_noticesincludes\absolute-plugins-services\class-license.php:222
actionadmin_menuincludes\absolute-plugins-services\class-license.php:550
actionactivated_pluginincludes\absolute-plugins-services\class-license.php:1320
actionswitch_themeincludes\absolute-plugins-services\class-license.php:1323
actionafter_switch_themeincludes\absolute-plugins-services\class-license.php:1324
actionafter_switch_themeincludes\absolute-plugins-services\class-license.php:1325
actionadmin_initincludes\absolute-plugins-services\class-promotions.php:92
actionadmin_noticesincludes\absolute-plugins-services\class-promotions.php:105
actionadmin_print_stylesincludes\absolute-plugins-services\class-promotions.php:107
actionadmin_enqueue_scriptsincludes\absolute-plugins-services\class-promotions.php:108
actionadmin_print_footer_scriptsincludes\absolute-plugins-services\class-promotions.php:109
filterpre_set_site_transient_update_pluginsincludes\absolute-plugins-services\class-updater.php:84
filterplugins_apiincludes\absolute-plugins-services\class-updater.php:85
filterpre_set_site_transient_update_themesincludes\absolute-plugins-services\class-updater.php:96
actionswitch_themeincludes\absolute-plugins-services\class-updater.php:97
actionadmin_initincludes\class-absolute-addons-services.php:118
filterabsp_service_api_is_debuggingincludes\class-absolute-addons-services.php:153
filterhttps_local_ssl_verifyincludes\class-absolute-addons-services.php:154
filterhttp_request_reject_unsafe_urlsincludes\class-absolute-addons-services.php:155
filterabsp_service_api_is_localincludes\class-absolute-addons-services.php:156
filterhttp_request_reject_unsafe_urlsincludes\class-absolute-addons-services.php:157
actionelementor/editor/footerincludes\class-absp-library.php:35
actionelementor/ajax/register_actionsincludes\class-absp-library.php:36
actioninitincludes\class-absp-post-types.php:12
actioninitincludes\class-absp-post-types.php:13
actionabsp/flush_rewrite_rulesincludes\class-absp-post-types.php:14
filterabsp/widgets/the_titleincludes\default-filters.php:19
filterabsp/widgets/the_titleincludes\default-filters.php:20
filterabsp/widgets/the_titleincludes\default-filters.php:21
filterabsp/widgets/the_titleincludes\default-filters.php:22
filterabsp/widgets/the_contentincludes\default-filters.php:23
filterabsp/widgets/the_contentincludes\default-filters.php:25
filterabsp/widgets/the_contentincludes\default-filters.php:26
filterabsp/widgets/the_contentincludes\default-filters.php:27
filterabsp/widgets/the_contentincludes\default-filters.php:28
filterabsp/widgets/the_contentincludes\default-filters.php:29
filterabsp/widgets/the_contentincludes\default-filters.php:30
filterabsp/widgets/the_contentincludes\default-filters.php:31
filterabsp/widgets/the_contentincludes\default-filters.php:33
filterabsp/widgets/the_excerptincludes\default-filters.php:35
filterabsp/widgets/the_excerptincludes\default-filters.php:36
filterabsp/widgets/the_excerptincludes\default-filters.php:37
filterabsp/widgets/the_excerptincludes\default-filters.php:38
filterabsp/widgets/the_excerptincludes\default-filters.php:39
filterabsp/widgets/the_excerptincludes\default-filters.php:40
filterabsp/widgets/the_excerptincludes\default-filters.php:41
filterplugins_api_resultincludes\default-filters.php:43
filterabsp/widgets/the_contentincludes\helper.php:441
filterabsp/widgets/the_excerptincludes\helper.php:517
filterelementor/icons_manager/nativeincludes\icons-manager.php:10
actionadmin_menuincludes\settings\class-dashboard.php:76
actionadmin_menuincludes\settings\class-dashboard.php:77
actionadmin_enqueue_scriptsincludes\settings\class-dashboard.php:78
filterwoocommerce_loop_add_to_cart_linkwidgets\product-grid\class-absolute-addons-style-product-grid.php:837
filteryith_wcwl_button_labelwidgets\product-grid\class-absolute-addons-style-product-grid.php:934
filteryith_wcwl_remove_from_wishlist_labelwidgets\product-grid\class-absolute-addons-style-product-grid.php:938
Maintenance & Trust

Absolute Addons For Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 13, 2022
PHP min version7.1
Downloads10K

Community Trust

Rating100/100
Number of ratings7
Active installs400
Developer Profile

Absolute Addons For Elementor Developer Profile

AbsolutePlugins

3 plugins · 420 total installs

72
trust score
Avg Security Score
69/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Absolute Addons For Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/absolute-addons/assets/css/frontend.css/wp-content/plugins/absolute-addons/assets/js/frontend.js/wp-content/plugins/absolute-addons/widgets/assets/css/widget.css/wp-content/plugins/absolute-addons/widgets/assets/js/widget.js
Script Paths
/wp-content/plugins/absolute-addons/assets/js/frontend.js/wp-content/plugins/absolute-addons/widgets/assets/js/widget.js
Version Parameters
absolute-addons/assets/css/frontend.css?ver=absolute-addons/assets/js/frontend.js?ver=absolute-addons/widgets/assets/css/widget.css?ver=absolute-addons/widgets/assets/js/widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
absp-element
Data Attributes
data-absp-widget-id
JS Globals
AbsoluteAddonsFrontend
FAQ

Frequently Asked Questions about Absolute Addons For Elementor