Media Player Addons for Elementor – Audio and Video Widgets for Elementor Security & Risk Analysis

wordpress.org/plugins/media-player-addons-for-elementor

Extend Elementor with powerful, customizable media players for audio, video, streaming & playlists.

1K active installs v1.1.3 PHP 7.1+ WP 4.7+ Updated Mar 14, 2026
elementor-addonmedia-playermp3-playervideo-playeryoutube
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 16, 2025
Safety Verdict

Is Media Player Addons for Elementor – Audio and Video Widgets for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

Media Player Addons for Elementor – Audio and Video Widgets for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 16, 2025Updated 20d ago
Risk Assessment

The security posture of the 'media-player-addons-for-elementor' plugin v1.1.3 appears to be generally strong, with no critical or high severity vulnerabilities identified in the static analysis or vulnerability history. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and having a high percentage of properly escaped output. Furthermore, the absence of file operations, external HTTP requests, and the presence of nonce and capability checks on its AJAX handlers contribute positively to its security.

However, there are a few areas that warrant attention. While the attack surface is small and appears to be protected by authentication, the fact that 3 AJAX handlers exist means there are potential entry points that require diligent verification. The vulnerability history, while currently clear, shows a past medium severity Cross-Site Scripting (XSS) vulnerability, indicating that robust input sanitization and output escaping are crucial for preventing future issues. The bundled Freemius library, while common, could also be a potential vector if it has known vulnerabilities in its version, though this is not explicitly stated in the provided data.

In conclusion, the plugin has a good foundation with secure coding practices in place for SQL and output handling. The lack of currently unpatched vulnerabilities is a positive sign. The primary risks lie in the continued vigilance required for the AJAX handlers and the potential for future vulnerabilities if past patterns of XSS are not thoroughly mitigated. The bundled library also presents a minor, unquantified risk.

Key Concerns

  • Medium severity past vulnerability (XSS)
  • Bundled library: Freemius v1.0 (potential for outdated)
  • 3 AJAX handlers, requires strict auth checks
Vulnerabilities
1

Media Player Addons for Elementor – Audio and Video Widgets for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-9203medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Media Player Addons for Elementor <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widget Fields

Sep 16, 2025 Patched in 1.0.6 (1d)
Code Analysis
Analyzed Mar 16, 2026

Media Player Addons for Elementor – Audio and Video Widgets for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
129 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

89% escaped145 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
mpafeGetBlocks (BMPAAdminMenu.php:36)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Media Player Addons for Elementor – Audio and Video Widgets for Elementor Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_bptbGetBlocksBMPAAdminMenu.php:9
authwp_ajax_allembed_install_pluginmedia-player-addons-for-elementor.php:123
authwp_ajax_allembed_activate_pluginmedia-player-addons-for-elementor.php:124
WordPress Hooks 19
actionadmin_menuBMPAAdminMenu.php:7
actionadmin_enqueue_scriptsBMPAAdminMenu.php:8
actionelementor/editor/after_enqueue_scriptsfreemius-extend\index.php:18
actionwp_footerfreemius-extend\index.php:19
actioninitmedia-player-addons-for-elementor.php:118
actionadmin_enqueue_scriptsmedia-player-addons-for-elementor.php:119
actionplugins_loadedmedia-player-addons-for-elementor.php:122
actionadmin_noticesmedia-player-addons-for-elementor.php:161
actionadmin_noticesmedia-player-addons-for-elementor.php:166
actionadmin_noticesmedia-player-addons-for-elementor.php:171
actionelementor/frontend/after_register_stylesplugin.php:284
actionadmin_enqueue_scriptsplugin.php:285
actionelementor/frontend/after_register_scriptsplugin.php:288
actionadmin_enqueue_scriptsplugin.php:289
actionelementor/widgets/registerplugin.php:292
actionelementor/elements/categories_registeredplugin.php:295
actionelementor/editor/after_enqueue_stylesplugin.php:296
actionelementor/frontend/after_register_stylesplugin.php:297
actionelementor/editor/after_enqueue_scriptsplugin.php:298
Maintenance & Trust

Media Player Addons for Elementor – Audio and Video Widgets for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version7.1
Downloads35K

Community Trust

Rating74/100
Number of ratings3
Active installs1K
Developer Profile

Media Player Addons for Elementor – Audio and Video Widgets for Elementor Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Media Player Addons for Elementor – Audio and Video Widgets for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/media-player-addons-for-elementor/assets/css/custom-style.css/wp-content/plugins/media-player-addons-for-elementor/assets/css/audio-widget.css/wp-content/plugins/media-player-addons-for-elementor/assets/css/video-widget.css/wp-content/plugins/media-player-addons-for-elementor/assets/css/video-playlist.css/wp-content/plugins/media-player-addons-for-elementor/assets/js/audio-widget.js/wp-content/plugins/media-player-addons-for-elementor/assets/js/video-widget.js/wp-content/plugins/media-player-addons-for-elementor/assets/js/video-playlist.js
Script Paths
/wp-content/plugins/media-player-addons-for-elementor/assets/js/audio-widget.js/wp-content/plugins/media-player-addons-for-elementor/assets/js/video-widget.js/wp-content/plugins/media-player-addons-for-elementor/assets/js/video-playlist.js
Version Parameters
media-player-addons-for-elementor/assets/css/custom-style.css?ver=media-player-addons-for-elementor/assets/css/audio-widget.css?ver=media-player-addons-for-elementor/assets/css/video-widget.css?ver=media-player-addons-for-elementor/assets/css/video-playlist.css?ver=media-player-addons-for-elementor/assets/js/audio-widget.js?ver=media-player-addons-for-elementor/assets/js/video-widget.js?ver=media-player-addons-for-elementor/assets/js/video-playlist.js?ver=

HTML / DOM Fingerprints

CSS Classes
audioplayeraudioplayer-containeraudioplayer-bodyvideo-player-wrapbpa-video-player-wrapbpa-video-player-wrap-innerbpa-video-playlist-wrapbpa-video-playlist-wrap-inner
HTML Comments
<!-- Plugin Name: Media Player Addons for Elementor – Audio and Video Widgets for Elementor --><!-- Plugin URI: https://elementoraddons.org/media-player-addons/ --><!-- Description: Collection of media players to plaback of various media files such as .mp3, .mp4, .flv, .m3u8, .ogg, YouTube, Vimeo and moe.... --><!-- Version: 1.1.3 -->+5 more
Data Attributes
data-settings
JS Globals
BMPA_VERSIONBMPA_DIR_URLBMPA_DIR_PATHMPAFE_HAS_PROmpafe_fsbaddon_main_element
FAQ

Frequently Asked Questions about Media Player Addons for Elementor – Audio and Video Widgets for Elementor