BWD Elementor Addons Security & Risk Analysis

wordpress.org/plugins/bwd-elementor-addons

The Addons bundle is a plugin that offers various widgets and preset designs to enhance the design capabilities of the page builder.

400 active installs v4.4.2 PHP 7.0+ WP 5.0+ Updated Jan 5, 2026
addonsdesigninterfacewebsite-elementswidgets
78
B · Generally Safe
CVEs total2
Unpatched1
Last CVEApr 4, 2025
Safety Verdict

Is BWD Elementor Addons Safe to Use in 2026?

Mostly Safe

Score 78/100

BWD Elementor Addons is generally safe to use. 2 past CVEs were resolved.

2 known CVEs 1 unpatched Last CVE: Apr 4, 2025Updated 4mo ago
Risk Assessment

The bwd-elementor-addons plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a well-structured codebase with a low attack surface, no obvious dangerous functions, and a strong reliance on prepared statements for SQL queries. The plugin also demonstrates good practices in output escaping, with a high percentage of outputs being properly handled, and a reasonable number of capability checks in place.

However, concerns arise from the vulnerability history. The presence of two known CVEs, one of which remains unpatched, is a significant red flag. The types of historical vulnerabilities (XSS and Information Exposure) suggest potential weaknesses in input sanitization or privilege escalation, which could be exploited if similar flaws exist in the current version. The fact that the last vulnerability was recorded in the future (2025-04-04) is unusual and may indicate a data anomaly, but the existence of unpatched vulnerabilities should not be disregarded.

While the static analysis shows no immediate critical issues, the unpatched CVE is the most pressing concern, indicating a known weakness that attackers could leverage. The plugin's strengths in code hygiene and attack surface management are commendable, but these are overshadowed by the persistent, unpatched vulnerability. Therefore, the overall risk is elevated due to the known exploitable flaw.

Key Concerns

  • Unpatched CVE
  • Bundled library: DataTables (potential for outdated versions)
  • Potential for unescaped output (16% unescaped)
Vulnerabilities
2 published

BWD Elementor Addons Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-32189medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BWD Elementor Addons <= 4.3.20 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 4, 2025Unpatched
CVE-2024-12532medium · 4.3Exposure of Sensitive Information to an Unauthorized Actor

BWD Elementor Addons <= 4.3.18 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates

Jan 6, 2025 Patched in 4.3.19 (1d)
Version History

BWD Elementor Addons Release Timeline

Code Analysis
Analyzed Mar 16, 2026

BWD Elementor Addons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
701
3660 escaped
Nonce Checks
1
Capability Checks
6
File Operations
2
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

Output Escaping

84% escaped4361 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
bwdeb_plugin_function_for_datas_callback (bwdeb-boots.php:572)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BWD Elementor Addons Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_bwdtsk_save_settingsbwdeb-boots.php:604
WordPress Hooks 15
filterplugin_action_linksbwd-elementor-addons.php:22
actionbwdeb_initbwd-elementor-addons.php:23
actionplugins_loadedbwd-elementor-addons.php:24
actionadmin_noticesbwd-elementor-addons.php:26
actionadmin_noticesbwd-elementor-addons.php:46
actionadmin_noticesbwd-elementor-addons.php:49
actioninitbwd-elementor-addons.php:57
actionadmin_menubwdeb-boots.php:590
actionadmin_enqueue_scriptsbwdeb-boots.php:591
actionelementor/editor/before_enqueue_scriptsbwdeb-boots.php:592
actionelementor/elements/categories_registeredbwdeb-boots.php:593
actionafter_setup_themebwdeb-boots.php:595
actionwp_enqueue_scriptsbwdeb-boots.php:598
actionelementor/widgets/registerbwdeb-boots.php:599
actionelementor/editor/after_enqueue_scriptsbwdeb-boots.php:603
Maintenance & Trust

BWD Elementor Addons Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 5, 2026
PHP min version7.0
Downloads19K

Community Trust

Rating100/100
Number of ratings25
Active installs400
Developer Profile

BWD Elementor Addons Developer Profile

Best WP Developer

11 plugins · 620 total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect BWD Elementor Addons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bwd-elementor-addons/assets/public/js/empty-dummy.js
Script Paths
/wp-content/plugins/bwd-elementor-addons/assets/public/js/empty-dummy.js
Version Parameters
bwd-elementor-addons/assets/public/js/empty-dummy.js?ver=bwd-elementor-addons/bwdeb-boots.php?ver=

HTML / DOM Fingerprints

CSS Classes
bwdeb_accordion2_titlebwdeb_team_carouselbwdeb-testimonial-sliderbwd-creative-buttonbwdeb_masking_wrapperbwdeb-service-showcase-itembwdeb-promo-box-wrapperbwdeb-service-flip-box-outer+5 more
HTML Comments
<!-- Start BWD Elementor Addons -> Meet The Team --><!-- End BWD Elementor Addons -> Meet The Team --><!-- Start BWD Elementor Addons -> Team Carousel --><!-- End BWD Elementor Addons -> Team Carousel -->+26 more
Data Attributes
data-bwdb-carousel-options
JS Globals
bwdeb_params
FAQ

Frequently Asked Questions about BWD Elementor Addons