Image Hover Effects – Elementor Addon Security & Risk Analysis

wordpress.org/plugins/image-hover-effects-addon-for-elementor

Add creative image hover effects to Elementor page builder. Easily customize title and content and effects with intuitive interface.

40K active installs v1.4.4 PHP 5.6+ WP 4.7+ Updated Jul 12, 2024
addonscss-effectselementorelementor-widgetimage-hover-effects
66
C · Use Caution
CVEs total5
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Image Hover Effects – Elementor Addon Safe to Use in 2026?

Use With Caution

Score 66/100

Image Hover Effects – Elementor Addon has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

5 known CVEs 1 unpatched Last CVE: Sep 22, 2025Updated 1yr ago
Risk Assessment

The plugin "image-hover-effects-addon-for-elementor" v1.4.4 exhibits a mixed security posture. While the code analysis shows no dangerous functions, no raw SQL queries, and no file operations, it also reveals significant weaknesses. A primary concern is the presence of one AJAX handler without any authentication checks, creating a direct entry point for potential unauthorized actions. Furthermore, a concerningly low rate of proper output escaping (46%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into user browsers.

The vulnerability history further amplifies these concerns. With five known CVEs, including one that remains unpatched, and a history of medium-severity vulnerabilities related to missing authorization and XSS, the plugin has a track record of security flaws. The fact that the last vulnerability was very recent (September 2025) indicates ongoing issues. While the plugin demonstrates some good practices like using prepared statements for SQL, the identified unprotected AJAX handler, the high percentage of unescaped output, and the recurring vulnerability types paint a picture of a plugin that requires immediate attention and mitigation to address its security weaknesses.

Key Concerns

  • Unprotected AJAX handler
  • Low percentage of output escaping
  • Unpatched CVE
  • Recurring XSS and authorization issues
Vulnerabilities
5 published

Image Hover Effects – Elementor Addon Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
3 CVEs in 2024
2024
1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
5

5 total CVEs

CVE-2025-57939medium · 5.4Missing Authorization

Image Hover Effects – Elementor Addon <= 1.4.4 - Missing Authorization

Sep 22, 2025Unpatched
CVE-2024-4780medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Image Hover Effects – Elementor Addon <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via eihe_link Parameter

Jul 15, 2024 Patched in 1.4.4 (1d)
CVE-2024-1166medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Image Hover Effects - Elementor Addon <= 1.4.1 - Authenticated(Contributor+) DOM-based Stored Cross-Site Scripting via Image Hover Effects Widget

May 6, 2024 Patched in 1.4.2 (4d)
CVE-2024-29936medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Image Hover Effects – Elementor Addon <= 1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'eihe_align'

Mar 25, 2024 Patched in 1.4.1 (8d)
CVE-2021-24264medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Image Hover Effects – Elementor Addon <= 1.3.3 - Authenticated Stored Cross-Site Scripting

Apr 13, 2021 Patched in 1.3.4 (1015d)
Code Analysis
Analyzed Mar 16, 2026

Image Hover Effects – Elementor Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
6 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

46% escaped13 total outputs
Attack Surface
1 unprotected

Image Hover Effects – Elementor Addon Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_eihe_top_noticeimage-hover-effects-addon-for-elementor.php:108
WordPress Hooks 11
actionplugins_loadedimage-hover-effects-addon-for-elementor.php:40
actionadmin_noticesimage-hover-effects-addon-for-elementor.php:46
actionadmin_noticesimage-hover-effects-addon-for-elementor.php:51
actionelementor/frontend/after_enqueue_stylesimage-hover-effects-addon-for-elementor.php:55
actionelementor/widgets/registerimage-hover-effects-addon-for-elementor.php:56
actionupgrader_process_completeimage-hover-effects-addon-for-elementor.php:57
actionadmin_enqueue_scriptsimage-hover-effects-addon-for-elementor.php:58
actionelementor/editor/before_enqueue_scriptsimage-hover-effects-addon-for-elementor.php:59
actionadmin_initimage-hover-effects-addon-for-elementor.php:63
filterwpml_elementor_widgets_to_translateimage-hover-effects-addon-for-elementor.php:65
actionadmin_noticesimage-hover-effects-addon-for-elementor.php:107
Maintenance & Trust

Image Hover Effects – Elementor Addon Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJul 12, 2024
PHP min version5.6
Downloads674K

Community Trust

Rating98/100
Number of ratings82
Active installs40K
Developer Profile

Image Hover Effects – Elementor Addon Developer Profile

Blocksera

2 plugins · 41K total installs

51
trust score
Avg Security Score
60/100
Avg Patch Time
307 days
View full developer profile
Detection Fingerprints

How We Detect Image Hover Effects – Elementor Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-hover-effects-addon-for-elementor/assets/admin.css/wp-content/plugins/image-hover-effects-addon-for-elementor/assets/admin.js/wp-content/plugins/image-hover-effects-addon-for-elementor/assets/style.min.css
Script Paths
/wp-content/plugins/image-hover-effects-addon-for-elementor/assets/admin.js
Version Parameters
/wp-content/plugins/image-hover-effects-addon-for-elementor/assets/admin.css?ver=/wp-content/plugins/image-hover-effects-addon-for-elementor/assets/admin.js?ver=/wp-content/plugins/image-hover-effects-addon-for-elementor/assets/style.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
eihe-noticeeihe-iconimgeihe-done
Data Attributes
data-eihe-titledata-eihe-description
JS Globals
eihe_top_notice
FAQ

Frequently Asked Questions about Image Hover Effects – Elementor Addon