JetWidgets for Elementor and WooCommerce Security & Risk Analysis

wordpress.org/plugins/jetwoo-widgets-for-elementor

JetWidgets for Elementor and WooCommerce is a plugin that allows adding WooCommerce Products and Categories into stylish grid and listing layouts to t …

8K active installs v1.1.9 PHP + WP 4.7+ Updated Apr 18, 2025
elementoronline-storeproduct-gridproducts-carouselproducts-list
90
A · Safe
CVEs total1
Unpatched0
Last CVEJul 19, 2024
Download
Safety Verdict

Is JetWidgets for Elementor and WooCommerce Safe to Use in 2026?

Generally Safe

Score 90/100

JetWidgets for Elementor and WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jul 19, 2024Updated 1yr ago
Risk Assessment

The "jetwoo-widgets-for-elementor" v1.1.9 plugin exhibits a mixed security posture. While the static analysis reveals a generally good implementation with 100% prepared SQL statements and a high percentage of properly escaped output, there are significant concerns regarding its attack surface. A critical finding is the presence of one AJAX handler that lacks authentication checks, presenting a direct entry point for potential attackers. The vulnerability history is also a cause for concern, with one high-severity "PHP Remote File Inclusion" vulnerability recorded recently. Although this specific vulnerability is currently unpatched, its nature suggests a history of weaknesses in handling file operations and user input, which could be indicative of underlying insecure coding practices that may not have been fully addressed.

Despite the positive indicators in SQL and output sanitization, the unprotected AJAX endpoint and the past high-severity RFI vulnerability highlight areas that require immediate attention. The lack of taint analysis findings could be due to the limited scope of the analysis or that specific exploit vectors were not identified. However, the combination of an unprotected entry point and historical RFI issues strongly suggests a higher risk than the other static analysis metrics might initially imply. The plugin is not without its strengths, particularly in its SQL handling and output escaping, but these are overshadowed by the identified entry points and historical vulnerabilities.

Key Concerns

  • Unprotected AJAX handler
  • History of high severity RFI vulnerability
Vulnerabilities
1 published

JetWidgets for Elementor and WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-38772high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

JetWidgets for Elementor and WooCommerce <= 1.1.7 - Authenticated (Contributor+) Limited Local File Inclusion

Jul 19, 2024 Patched in 1.1.8 (7d)
Version History

JetWidgets for Elementor and WooCommerce Release Timeline

v1.1.9Current
v1.1.8
v1.1.71 CVE
v1.1.61 CVE
v1.1.51 CVE
v1.1.41 CVE
v1.1.31 CVE
v1.1.21 CVE
v1.1.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

JetWidgets for Elementor and WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
24
291 escaped
Nonce Checks
1
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared3 total queries

Output Escaping

92% escaped315 total outputs
Attack Surface
1 unprotected

JetWidgets for Elementor and WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_elementor_render_widgetincludes\integrations\base\class-jet-woo-widgets-integration.php:48
WordPress Hooks 30
actionadmin_enqueue_scriptsframework\interface-builder\cherry-x-interface-builder.php:151
actionwp_enqueue_scriptsframework\interface-builder\inc\class-cx-controls-base.php:52
actionadmin_enqueue_scriptsframework\interface-builder\inc\class-cx-controls-base.php:53
actionadmin_footerframework\interface-builder\inc\controls\iconpicker.php:85
actioncustomize_controls_print_footer_scriptsframework\interface-builder\inc\controls\iconpicker.php:86
filtercx_handler_response_dataframework\interface-builder\inc\controls\iconpicker.php:87
filtercx_control/add_repeater_dataframework\interface-builder\inc\controls\iconpicker.php:179
actionadmin_footerframework\interface-builder\inc\controls\repeater.php:80
actioncustomize_controls_print_footer_scriptsframework\interface-builder\inc\controls\repeater.php:81
filtercx_control/is_repeaterframework\interface-builder\inc\controls\repeater.php:119
actionafter_setup_themeframework\loader.php:83
actionafter_setup_themeframework\loader.php:84
actionwp_enqueue_scriptsincludes\class-jet-woo-widgets-assets.php:28
actionelementor/frontend/before_enqueue_scriptsincludes\class-jet-woo-widgets-assets.php:30
actionelementor/frontend/after_enqueue_scriptsincludes\class-jet-woo-widgets-assets.php:31
actionadmin_enqueue_scriptsincludes\class-jet-woo-widgets-assets.php:32
actioninitincludes\class-jet-woo-widgets-shortcodes.php:43
actionelementor/initincludes\integrations\base\class-jet-woo-widgets-integration.php:44
actionelementor/widgets/widgets_registeredincludes\integrations\base\class-jet-woo-widgets-integration.php:46
actionelementor/editor/after_enqueue_stylesincludes\integrations\base\class-jet-woo-widgets-integration.php:50
actionelementor/controls/controls_registeredincludes\integrations\base\class-jet-woo-widgets-integration.php:52
actiontemplate_redirectincludes\integrations\base\class-jet-woo-widgets-integration.php:54
actionadmin_enqueue_scriptsincludes\settings\class-jet-woo-widgets-settings.php:61
actionadmin_menuincludes\settings\class-jet-woo-widgets-settings.php:62
actioninitincludes\settings\class-jet-woo-widgets-settings.php:63
actionadmin_noticesincludes\settings\class-jet-woo-widgets-settings.php:64
actionafter_setup_themejetwoo-widgets-for-elementor.php:78
actioninitjetwoo-widgets-for-elementor.php:81
actioninitjetwoo-widgets-for-elementor.php:83
actiontgmpa_registerjetwoo-widgets-for-elementor.php:146
Maintenance & Trust

JetWidgets for Elementor and WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 18, 2025
PHP min version
Downloads142K

Community Trust

Rating86/100
Number of ratings7
Active installs8K
Developer Profile

JetWidgets for Elementor and WooCommerce Developer Profile

jetmonsters

33 plugins · 326K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
187 days
View full developer profile
Detection Fingerprints

How We Detect JetWidgets for Elementor and WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jetwoo-widgets-for-elementor/assets/css/jet-woo-widgets.css/wp-content/plugins/jetwoo-widgets-for-elementor/assets/js/jet-woo-widgets.js
Script Paths
/wp-content/plugins/jetwoo-widgets-for-elementor/assets/js/jet-woo-widgets.js
Version Parameters
jetwoo-widgets-for-elementor/assets/css/jet-woo-widgets.css?ver=jetwoo-widgets-for-elementor/assets/js/jet-woo-widgets.js?ver=

HTML / DOM Fingerprints

CSS Classes
jet-woo-widgets-product-navigationjet-woo-widgets-breadcrumbsjet-woo-widgets-product-gallery
Data Attributes
data-product-iddata-action
JS Globals
JetWooWidgetsConfig
FAQ

Frequently Asked Questions about JetWidgets for Elementor and WooCommerce