
Black Widgets For Elementor Security & Risk Analysis
wordpress.org/plugins/black-widgetsFree add-on for Elementor! With this add-on, you can add more visual effects and improve your website's user experience. ✌
Is Black Widgets For Elementor Safe to Use in 2026?
Use With Caution
Score 68/100Black Widgets For Elementor has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "black-widgets" plugin version 1.3.9 presents a mixed security posture. While the static analysis indicates a lack of direct attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, and all SQL queries utilize prepared statements, there are significant concerns regarding output escaping. With only 58% of outputs properly escaped, there is a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, especially considering that XSS is the common vulnerability type in its history.
The vulnerability history is a major red flag. The plugin has a total of 6 known CVEs, with one still unpatched. All of these past vulnerabilities are rated as medium severity, and they predominantly fall under Cross-Site Scripting. This pattern suggests a recurring weakness in how the plugin handles user-supplied data and prevents it from being interpreted as executable code within the browser. The most recent vulnerability occurring in April 2025 is particularly concerning, indicating ongoing issues that have not been fully addressed.
In conclusion, despite the absence of obvious code execution pathways and the proper use of prepared statements for SQL, the plugin's history of numerous XSS vulnerabilities and the current unpatched medium-severity CVE indicate a substantial security risk. The poor output escaping further exacerbates this risk. Users should exercise extreme caution and consider alternatives if a more robust security posture is required.
Key Concerns
- Unpatched CVEs (Medium severity)
- 58% output escaping (potential XSS)
- High number of past CVEs (6 total)
- Common vulnerability type: XSS
Black Widgets For Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Black Widgets For Elementor <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Black Widgets For Elementor <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Black Widgets For Elementor <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Black Widgets For Elementor <= 1.3.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Black Widgets For Elementor <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Black Widgets For Elementor <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Black Widgets For Elementor Code Analysis
Output Escaping
Black Widgets For Elementor Attack Surface
WordPress Hooks 20
Maintenance & Trust
Black Widgets For Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Black Widgets For Elementor Alternatives
HT Mega Addons for Elementor – Elementor Widgets & Template Builder
ht-mega-for-elementor
Elementor addon offering 135+ widgets — Mega Menu, Ready Templates, Page Builder, Slider, Gallery, Post Grid, AI Writer & more.
Livemesh Addons by Elementor
addons-for-elementor
Elementor Addons that saves time with multiple ready-to-use drag and drop styles for 30+ essential widgets built for Elementor page builder.
Move Addons for Elementor
move-addons
Move Addons is a WordPress plugin for Elementor page builder, is a powerful tool that helps you to make almost every possible customization to your we …
Creative Addons for Elementor
creative-addons-for-elementor
Write articles and documents faster and more easily using our powerful and practical Elementor widgets.
Easy Elements for Elementor – Addons & Website Templates
easy-elements
Modern Elementor Addons: A lightweight, powerful addon with beautifully designed widgets and extensions to build creative, animated websites.
Black Widgets For Elementor Developer Profile
2 plugins · 930 total installs
How We Detect Black Widgets For Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/black-widgets/includes/admin/css/black-widgets-elementor.css/wp-content/plugins/black-widgets/includes/admin/css/black-widgets-admin.css/wp-content/plugins/black-widgets/includes/admin/js/black-widgets-admin.jswp-content/plugins/black-widgets/includes/admin/js/black-widgets-admin.jsblack-widgets-elementor.css?ver=black-widgets-admin.css?ver=black-widgets-admin.js?ver=HTML / DOM Fingerprints
bw-widgetbw-sectionbw-column<!-- Black Widgets Admin Area --><!-- Black Widgets Settings -->data-bw-widget-iddata-bw-settingsbwAdminblackWidgets[bw_widget[bw_section][bw_column