EleSpare – News, Magazine and Blog Addons for Elementor Security & Risk Analysis

wordpress.org/plugins/elespare

EleSpare provides pre-designed templates, header/footer builders, and various post layouts for creating stunning news, magazine, and blog sites with E …

10K active installs v3.3.10 PHP 5.3+ WP + Updated Feb 24, 2026
elementorelementor-addonselementor-post-gridelementor-templateswidgets-for-elementor
99
A · Safe
CVEs total2
Unpatched0
Last CVEJun 12, 2024
Safety Verdict

Is EleSpare – News, Magazine and Blog Addons for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

EleSpare – News, Magazine and Blog Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jun 12, 2024Updated 1mo ago
Risk Assessment

The "elespare" plugin v3.3.10 exhibits a mixed security posture. On one hand, the static analysis reveals positive practices such as 100% use of prepared statements for SQL queries, a high rate of proper output escaping (97%), and robust use of nonce and capability checks. However, there are significant concerns regarding the attack surface. Specifically, 2 out of 6 entry points, consisting of REST API routes, lack permission callbacks, making them potentially accessible to unauthorized users. The taint analysis shows no unsanitized paths, which is a strong positive indicator. The vulnerability history reveals a pattern of past vulnerabilities, including Cross-site Scripting and Missing Authorization, with two medium-severity CVEs historically. While currently unpatched vulnerabilities are zero, the past incidents, especially those related to authorization, align with the observed unprotected REST API routes, highlighting a persistent area of risk that needs careful monitoring and remediation.

Despite the absence of critical findings in the current static and taint analysis and the lack of currently unpatched vulnerabilities, the presence of unprotected REST API endpoints is a direct security concern. This, coupled with the historical pattern of authorization and XSS vulnerabilities, suggests that the plugin, while improving, has had past weaknesses in input validation and access control. The overall security is decent due to good SQL and output handling, but the unprotected entry points represent a clear and present risk. The bundled Freemius library, while version 1.0, is not flagged as outdated by the provided data, but should be a consideration for future checks if more detailed information were available. The conclusion is that the plugin is generally well-coded but has specific, exploitable weaknesses in its access control mechanisms for its REST API.

Key Concerns

  • REST API routes without permission callbacks
  • Historically vulnerable to XSS and Missing Authorization
Vulnerabilities
2

EleSpare – News, Magazine and Blog Addons for Elementor Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-4615medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Elespare – Blog, Magazine and Newspaper Addons for Elementor with Templates, Widgets, Kits, and Header/Footer Builder. One Click Import: No Coding Required! <= 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Horizontal Nav Menu Widget

Jun 12, 2024 Patched in 3.2.0 (8d)
CVE-2024-0900medium · 4.3Missing Authorization

Elespare – Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding Skills Required! <= 2.1.2 - Missing Authorization to Subscriber+ Arbitrary Post Creation

Apr 22, 2024 Patched in 2.1.3 (1d)
Code Analysis
Analyzed Mar 16, 2026

EleSpare – News, Magazine and Blog Addons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
486 escaped
Nonce Checks
4
Capability Checks
7
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

97% escaped503 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<class-metabox> (header-footer\inc\admin\class-metabox.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

EleSpare – News, Magazine and Blog Addons for Elementor Attack Surface

Entry Points6
Unprotected2

AJAX Handlers 2

authwp_ajax_elespare_create_postheader-footer\inc\admin\class-admin.php:34
noprivwp_ajax_elespare_create_postheader-footer\inc\admin\class-admin.php:35

REST API Routes 2

GET/wp-json/elespare/v1template-listsinc\request-rest-api.php:20
GET/wp-json/elespare/v1import-templateinc\request-rest-api.php:33

Shortcodes 2

[es_current_year] src\widgets\copyright\copyright-shortcode.php:17
[es_site_title] src\widgets\copyright\copyright-shortcode.php:18
WordPress Hooks 48
actionelementor/widgets/registerclass-elespare.php:146
actionwp_enqueue_scriptsclass-elespare.php:147
actionelementor/editor/after_enqueue_scriptsclass-elespare.php:150
filterelementor/editor/localize_settingsclass-elespare.php:151
actioninitelespare.php:83
actionplugins_loadedelespare.php:86
actionelementor/frontend/after_enqueue_styleselespare.php:89
actionelementor/elements/categories_registeredelespare.php:91
actionactivated_pluginelespare.php:93
filterplugin_row_metaelespare.php:95
actionelementor/editor/before_enqueue_scriptselespare.php:135
actionadmin_noticeselespare.php:141
actionadmin_noticeselespare.php:147
actionadmin_noticeselespare.php:153
actionwpheader-footer\class-template.php:34
actionwp_headheader-footer\class-template.php:35
actionwp_enqueue_scriptsheader-footer\class-template.php:36
filtersingle_templateheader-footer\class-template.php:37
actionelespare_hf_get_headerheader-footer\class-template.php:38
actionelespare_hf_get_header_wrapperheader-footer\class-template.php:39
actionelespare_hf_get_footer_wrapperheader-footer\class-template.php:40
actionelespare_hf_get_footerheader-footer\class-template.php:41
actionget_headerheader-footer\class-template.php:48
actionget_footerheader-footer\class-template.php:49
actionadmin_menuheader-footer\inc\admin\class-admin-dashboard.php:18
actionadmin_headheader-footer\inc\admin\class-admin-dashboard.php:81
actionadmin_enqueue_scriptsheader-footer\inc\admin\class-admin.php:28
filtermanage_elespare_builder_posts_columnsheader-footer\inc\admin\class-admin.php:29
actionmanage_elespare_builder_posts_custom_columnheader-footer\inc\admin\class-admin.php:30
actionadmin_footerheader-footer\inc\admin\class-admin.php:31
actionadd_meta_boxesheader-footer\inc\admin\class-metabox.php:15
actionsave_postheader-footer\inc\admin\class-metabox.php:16
actioninitheader-footer\init.php:47
actionadmin_menuinc\admin\class-admin-dashboard.php:18
actionadmin_enqueue_scriptsinc\admin\class-admin-dashboard.php:19
actionadmin_headinc\admin\class-admin-dashboard.php:110
actioninitinc\admin\class-base.php:65
actioninitinc\admin\create-page.php:13
actionadmin_enqueue_scriptsinc\admin\create-page.php:14
actionadmin_noticesinc\admin\notice-upgrade.php:22
actionadmin_headinc\admin\notice-upgrade.php:23
actionelementor/preview/enqueue_stylesinc\init.php:40
actionelementor/initinc\init.php:41
actionrest_api_initinc\init.php:42
actionadmin_enqueue_scriptsinc\init.php:43
actionplugins_loadedinc\init.php:88
actionelespare_hf_seach_formsrc\hooks\class-hooks.php:14
filterwalker_nav_menu_start_elsrc\widgets\nav-menu-horizontal\widget.php:860
Maintenance & Trust

EleSpare – News, Magazine and Blog Addons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 24, 2026
PHP min version5.3
Downloads538K

Community Trust

Rating98/100
Number of ratings44
Active installs10K
Developer Profile

EleSpare – News, Magazine and Blog Addons for Elementor Developer Profile

Elespare

1 plugin · 10K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect EleSpare – News, Magazine and Blog Addons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elespare/dist/elespare.style.build.min.css
Version Parameters
elespare-posts-grid

HTML / DOM Fingerprints

CSS Classes
elespare-pro-link
FAQ

Frequently Asked Questions about EleSpare – News, Magazine and Blog Addons for Elementor