Classic Addons – WPBakery Page Builder Security & Risk Analysis

wordpress.org/plugins/classic-addons-wpbakery-page-builder-addons

15+ Beautiful and Powerful Addons for WPBakery Page Builder (Visual Composer)

3K active installs v3.7 PHP + WP 3.5+ Updated Dec 4, 2025
ui-addonswpbakerywpbakery-addonswpbakery-page-builderwpbakery-page-builder-addons
96
A · Safe
CVEs total3
Unpatched0
Last CVEJan 3, 2025
Safety Verdict

Is Classic Addons – WPBakery Page Builder Safe to Use in 2026?

Generally Safe

Score 96/100

Classic Addons – WPBakery Page Builder has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Jan 3, 2025Updated 4mo ago
Risk Assessment

The static analysis of Classic Addons WP Bakery Page Builder Addons v3.7 shows a generally strong security posture with several good practices in place. The plugin boasts a high percentage of properly escaped outputs and utilizes prepared statements exclusively for SQL queries, which significantly mitigates common vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. Furthermore, the fact that all identified entry points have at least one nonce check is a positive sign, indicating an effort to prevent CSRF attacks.

However, a significant concern arises from the plugin's vulnerability history. With a total of three known CVEs, two of which are high severity, and past instances of critical vulnerabilities like Remote File Inclusion and Path Traversal, this indicates a recurring pattern of security weaknesses. The presence of Cross-Site Scripting as a common vulnerability type, even if not explicitly flagged in the current static analysis, is concerning given the past issues.

While the current version (v3.7) shows no unpatched vulnerabilities and a clean taint analysis, the historical context cannot be ignored. The plugin has a history of critical security flaws, suggesting a need for more robust and consistent security practices. The lack of capability checks on its single AJAX handler, coupled with the past vulnerabilities, presents a potential risk if the AJAX handler processes user input without proper authorization, even if current taint analysis shows no issues. This history warrants careful monitoring and a cautious approach to its deployment.

Key Concerns

  • Historical high-severity vulnerabilities (2)
  • Historical medium-severity vulnerability (1)
  • Lack of capability checks on AJAX handler
  • Past Cross-site Scripting vulnerabilities
Vulnerabilities
3

Classic Addons – WPBakery Page Builder Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
2
Medium
1

3 total CVEs

CVE-2024-56286high · 7.2Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Classic Addons – WPBakery Page Builder <= 3.0 - Authenticated (Editor+) Local File Inclusion

Jan 3, 2025 Patched in 3.1 (6d)
CVE-2024-11952high · 7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Classic Addons – WPBakery Page Builder <= 3.0 - Authenticated (Contributor+) Limited Local PHP File Inclusion

Dec 3, 2024 Patched in 3.1 (1d)
CVE-2024-43953medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Classic Addons – WPBakery Page Builder <= 3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 26, 2024 Patched in 3.6 (319d)
Code Analysis
Analyzed Mar 16, 2026

Classic Addons – WPBakery Page Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
41
713 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped754 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save_settings (classes\addons.class.php:210)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Classic Addons – WPBakery Page Builder Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_caw_settings_actionclasses\addons.class.php:15
WordPress Hooks 11
actionvc_before_initclasses\addons.class.php:9
actionvc_load_default_paramsclasses\addons.class.php:10
actionwp_enqueue_scriptsclasses\addons.class.php:11
actionadmin_enqueue_scriptsclasses\addons.class.php:12
actionadmin_menuclasses\addons.class.php:14
actioninitclasses\addons.class.php:16
actionadmin_noticesclasses\addons.class.php:21
actionwcp_testimonial_display_ratingclasses\hooks.class.php:9
actionwcp_testimonial_display_companyclasses\hooks.class.php:10
actioncaw_render_icon_componentclasses\hooks.class.php:11
actioncaw_render_button_componentclasses\hooks.class.php:12
Maintenance & Trust

Classic Addons – WPBakery Page Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version
Downloads29K

Community Trust

Rating100/100
Number of ratings1
Active installs3K
Developer Profile

Classic Addons – WPBakery Page Builder Developer Profile

webcodingplace

4 plugins · 5K total installs

76
trust score
Avg Security Score
83/100
Avg Patch Time
49 days
View full developer profile
Detection Fingerprints

How We Detect Classic Addons – WPBakery Page Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/classic-addons-wpbakery-page-builder-addons/addons/alert-box/alert-box.css/wp-content/plugins/classic-addons-wpbakery-page-builder-addons/addons/alert-box/alert-box.js/wp-content/plugins/classic-addons-wpbakery-page-builder-addons/addons/animated-heading/animated-heading.css/wp-content/plugins/classic-addons-wpbakery-page-builder-addons/addons/animated-heading/animated-heading.js
Script Paths
/wp-content/plugins/classic-addons-wpbakery-page-builder-addons/addons/alert-box/alert-box.js/wp-content/plugins/classic-addons-wpbakery-page-builder-addons/addons/animated-heading/animated-heading.js
Version Parameters
classic-addons-wpbakery-page-builder-addons/addons/alert-box/alert-box.css?ver=classic-addons-wpbakery-page-builder-addons/addons/alert-box/alert-box.js?ver=classic-addons-wpbakery-page-builder-addons/addons/animated-heading/animated-heading.css?ver=classic-addons-wpbakery-page-builder-addons/addons/animated-heading/animated-heading.js?ver=

HTML / DOM Fingerprints

CSS Classes
caw-alert-boxcaw-style-top-iconcaw-dismissiblecaw-alert-closecaw-alert-contentcaw-alert-titlecaw-aheading
Data Attributes
data-dismiss-target
Shortcode Output
<div id="caw-alert-<button type="button" class="caw-alert-close"<div class="caw-alert-content"><h3 class="caw-alert-title
FAQ

Frequently Asked Questions about Classic Addons – WPBakery Page Builder