
Essential Addons for Elementor – Popular Elementor Templates & Widgets Security & Risk Analysis
wordpress.org/plugins/essential-addons-for-elementor-liteElementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Is Essential Addons for Elementor – Popular Elementor Templates & Widgets Safe to Use in 2026?
Mostly Safe
Score 76/100Essential Addons for Elementor – Popular Elementor Templates & Widgets is generally safe to use. 56 past CVEs were resolved. Keep it updated.
Essential Addons for Elementor Lite v6.5.13 presents a mixed security posture. While the plugin demonstrates good practices with a high percentage of SQL queries using prepared statements and a significant majority of outputs being properly escaped, there are notable concerns. The presence of 14 unprotected AJAX handlers is a significant weakness, creating a large attack surface that could be exploited by unauthenticated users. The use of the `unserialize` function, a known dangerous function, also warrants caution. The plugin's vulnerability history is concerning, with a substantial number of known CVEs, including critical and high-severity issues. Although there are currently no unpatched vulnerabilities, the sheer volume and recurring types of past vulnerabilities (Missing Authorization, XSS, Deserialization) suggest a pattern of security weaknesses that require vigilant monitoring and prompt patching. The plugin has a relatively large attack surface with a notable proportion of unprotected entry points, which is a primary concern. The taint analysis, while showing no critical or high severity flows, still identified unsanitized paths, which could potentially lead to vulnerabilities if not addressed.
Key Concerns
- 14 unprotected AJAX handlers
- Use of 'unserialize' dangerous function
- 3 unsanitized paths in taint analysis
- 56 total known CVEs
- 2 critical severity CVEs in history
- 5 high severity CVEs in history
- Frequent past vulnerability types (auth, XSS, deserialization)
Essential Addons for Elementor – Popular Elementor Templates & Widgets Security Vulnerabilities
CVEs by Year
Severity Breakdown
56 total CVEs
Essential Addons for Elementor <= 6.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget
Essential Addons for Elementor <= 6.5.5 - Missing Authorization to Unauthenticated Sensitive Information Exposure
Essential Addons for Elementor <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor <= 6.2.4 - Missing Authorization
Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items'
Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget
Essential Addons for Elementor <= 6.1.9 - Authenticated (Contributor+) Information Disclosure
Essential Addons for Elementor <= 6.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor <= 6.0.14 - Reflected Cross-Site Scripting
Essential Addons for Elementor <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation
Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Contributor+) Sensitive Information Exposure
Essential Addons for Elementor <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery Widget
Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via no_more_items_text Parameter
Essential Addons for Elementor <= 5.9.26 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.23 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.22 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor <= 5.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Feed
Essential Addons for Elementor <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.20 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table'
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Interactive Circles'
Essential Addons for Elementor <= 5.9.19 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Several Widgets
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information Exposure
Essential Addons for Elementor <= 5.9.14 - Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute
Essential Addons for Elementor <= 5.9.13 - Authenticated (Author+) PHP Object Injection via error_resetpassword
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 - Unauthenticated Sensitive Information Exposure
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scritping
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Essential Addons for Elementor <= 5.8.8 - Authenticated (Contributor+) Privilege Escalation
Essential Addons For Elementor <=5.8.1 - Unauthenticated MailChimp API Key Disclosure
Essential Addons for Elementor <= 5.7.1 - Unauthenticated Arbitrary Password Reset to Privilege Escalation
Essential Addons for Elementor Lite <= 5.0.8 - Reflected Cross-Site Scripting
Essential Addons for Elementor <= 5.0.4 - Local File Inclusion
Essential Addons for Elementor <= 4.6.4 - Missing Authorization
Essential Addons for Elementor <= 4.6.4 - Authenticated (Contributor+) Privilege Escalation
Essential Addons for Elementor Lite <= 4.5.3 - Cross-Site Scripting
Essential Addons for Elementor – Popular Elementor Templates & Widgets Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Essential Addons for Elementor – Popular Elementor Templates & Widgets Attack Surface
AJAX Handlers 37
WordPress Hooks 201
Maintenance & Trust
Essential Addons for Elementor – Popular Elementor Templates & Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Essential Addons for Elementor – Popular Elementor Templates & Widgets Alternatives
RTMKit
rometheme-for-elementor
All-in-one toolkit for Elementor: advanced addons, theme builder, forms, icons & templates to build stunning sites fast and easy.
Turbo Addons Elementor
turbo-addons-elementor
Turbo Addons for Elementor offers advanced widgets to enhance Elementor, helping you create professional, interactive websites easily and quickly.
Essential Classy Addons – Widgets & Templates for Elementor
essential-classy-addons-for-elementor
Post Grid, Woocommerce builder Widgets. Slider, Carousel, Testimonial.A lightweight collection of ready-to-use widgets, templates, and extensions.
Selleradise Elements – Elementor Addons
selleradise-widgets
Selleradise Elements adds powerful Elementor widgets and WooCommerce integrations for beautiful, conversion-focused sites.
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Essential Addons for Elementor – Popular Elementor Templates & Widgets Developer Profile
46 plugins · 4.0M total installs
How We Detect Essential Addons for Elementor – Popular Elementor Templates & Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.