Mega Elements – Addons for Elementor Security & Risk Analysis

wordpress.org/plugins/mega-elements-addons-for-elementor

A powerful and advanced all in one Elementor addons with unique styling features to create a beautiful website effortlessly.

10K active installs v1.3.4 PHP 7.4+ WP 5.0+ Updated Nov 5, 2025
elementorelementor-addonselementor-widgetselementsmega-elements
96
A · Safe
CVEs total6
Unpatched0
Last CVESep 25, 2025
Safety Verdict

Is Mega Elements – Addons for Elementor Safe to Use in 2026?

Generally Safe

Score 96/100

Mega Elements – Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

6 known CVEsLast CVE: Sep 25, 2025Updated 4mo ago
Risk Assessment

The plugin "mega-elements-addons-for-elementor" v1.3.4 presents a mixed security posture. While the code analysis indicates good practices in several areas, such as 100% use of prepared statements for SQL queries and a high percentage of properly escaped output, there are significant concerns regarding its attack surface. The plugin exposes three AJAX handlers, all of which lack authentication checks, creating a direct pathway for attackers to interact with potentially sensitive functionalities without proper authorization. The absence of taint analysis results is noted, but this doesn't negate the identified direct vulnerabilities.

The plugin's vulnerability history is a major red flag. With six known medium-severity CVEs, despite none being currently unpatched, it indicates a pattern of introducing vulnerabilities, particularly Cross-Site Scripting (XSS) flaws. The fact that the last vulnerability was recorded in 2025-09-25, which is in the future, suggests a potential data anomaly or an outdated vulnerability database. However, the consistent history of medium-severity issues points to recurring coding weaknesses that need to be addressed to improve the plugin's overall security. The presence of file operations without explicit context in the static analysis also warrants careful scrutiny, although no specific vulnerabilities were directly flagged in that area by the provided data.

In conclusion, while the plugin demonstrates strengths in database interaction and output sanitization, the unprotected AJAX endpoints and the historical prevalence of XSS vulnerabilities represent critical weaknesses. The plugin's security can be significantly improved by implementing robust authentication and authorization checks on all entry points and diligently addressing the root causes of past XSS vulnerabilities. The future-dated vulnerability is a point of confusion and should be verified or corrected.

Key Concerns

  • Unprotected AJAX handlers
  • History of 6 medium severity CVEs
  • Unescaped output rate (22% unescaped)
  • File operation detected
Vulnerabilities
6

Mega Elements – Addons for Elementor Security Vulnerabilities

CVEs by Year

5 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
6

6 total CVEs

CVE-2025-8200medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mega Elements – Addons for Elementor <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer Widget

Sep 25, 2025 Patched in 1.3.3 (1d)
CVE-2024-49693medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mega Elements <= 1.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 21, 2024 Patched in 1.2.7 (10d)
CVE-2024-47343medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mega Elements <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 27, 2024 Patched in 1.2.5 (7d)
CVE-2024-37466medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mega Elements <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jul 1, 2024 Patched in 1.2.3 (9d)
CVE-2024-4702medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mega Elements <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget

May 14, 2024 Patched in 1.2.2 (1d)
CVE-2024-32575medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mega Elements <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 16, 2024 Patched in 1.2.0 (9d)
Code Analysis
Analyzed Mar 16, 2026

Mega Elements – Addons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
164
581 escaped
Nonce Checks
1
Capability Checks
4
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped745 total outputs
Attack Surface
3 unprotected

Mega Elements – Addons for Elementor Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_meafe_products_tab_contentincludes\meafe-helpers.php:505
noprivwp_ajax_meafe_products_tab_contentincludes\meafe-helpers.php:506
authwp_ajax_elementor_ajaxplugin.php:46
WordPress Hooks 25
actionadmin_menuincludes\classes\class-dashboard.php:28
actionadmin_menuincludes\classes\class-dashboard.php:29
actionadmin_enqueue_scriptsincludes\classes\class-dashboard.php:30
actionewfe_save_dashboard_dataincludes\classes\class-dashboard.php:34
actionin_admin_headerincludes\classes\class-dashboard.php:35
actionelementor/widgets/registerincludes\classes\class-widgets-manager.php:23
actioncategory_add_form_fieldsincludes\meafe-helpers.php:302
actioncreated_categoryincludes\meafe-helpers.php:303
actioncategory_edit_form_fieldsincludes\meafe-helpers.php:304
actionedited_categoryincludes\meafe-helpers.php:305
filtermanage_edit-category_columnsincludes\meafe-helpers.php:306
actionmanage_category_custom_columnincludes\meafe-helpers.php:307
actionadmin_footerincludes\meafe-helpers.php:308
filterbt_newsletter_shortcode_inner_wrap_displayincludes\meafe-helpers.php:327
actionbt_newsletter_shortcode_inner_wrap_startincludes\meafe-helpers.php:334
actionbt_newsletter_shortcode_inner_wrap_closeincludes\meafe-helpers.php:341
actionplugins_loadedplugin.php:34
actionelementor/initplugin.php:35
actionelementor/editor/before_enqueue_scriptsplugin.php:36
actionelementor/frontend/after_register_scriptsplugin.php:37
actionelementor/frontend/after_register_stylesplugin.php:38
actionadmin_enqueue_scriptsplugin.php:39
actionadmin_noticesplugin.php:191
actionadmin_noticesplugin.php:197
actionadmin_noticesplugin.php:203
Maintenance & Trust

Mega Elements – Addons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 5, 2025
PHP min version7.4
Downloads282K

Community Trust

Rating100/100
Number of ratings1
Active installs10K
Developer Profile

Mega Elements – Addons for Elementor Developer Profile

Kraft Plugins

5 plugins · 23K total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Mega Elements – Addons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mega-elements-addons-for-elementor/assets/admin/dashboard/css/sweetalert.css/wp-content/plugins/mega-elements-addons-for-elementor/assets/admin/dashboard/js/sweetalert.js/wp-content/plugins/mega-elements-addons-for-elementor/assets/admin/dashboard/css/dashboard.css/wp-content/plugins/mega-elements-addons-for-elementor/assets/admin/dashboard/js/dashboard.js
Version Parameters
mega-elements-addons-for-elementor/assets/admin/dashboard/css/sweetalert.css?ver=mega-elements-addons-for-elementor/assets/admin/dashboard/js/sweetalert.js?ver=mega-elements-addons-for-elementor/assets/admin/dashboard/css/dashboard.css?ver=mega-elements-addons-for-elementor/assets/admin/dashboard/js/dashboard.js?ver=

HTML / DOM Fingerprints

CSS Classes
mega-elements-menu-item
HTML Comments
<!-- Mega Elements Dashbord Start --><!-- Mega Elements Dashbord End -->
Data Attributes
data-slug="mega-elements"data-nonce="ewfe_save_dashboard"data-action="ewfe_save_dashboard"
JS Globals
MegaElementsAddons
FAQ

Frequently Asked Questions about Mega Elements – Addons for Elementor