Move Addons for Elementor Security & Risk Analysis

wordpress.org/plugins/move-addons

Move Addons is a WordPress plugin for Elementor page builder, is a powerful tool that helps you to make almost every possible customization to your we …

3K active installs v1.3.8 PHP + WP 5.0+ Updated Dec 4, 2025
elementorelementor-addonselementor-blockselementor-page-builderelementor-widgets
97
A · Safe
CVEs total8
Unpatched0
Last CVEDec 30, 2024
Safety Verdict

Is Move Addons for Elementor Safe to Use in 2026?

Generally Safe

Score 97/100

Move Addons for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

8 known CVEsLast CVE: Dec 30, 2024Updated 4mo ago
Risk Assessment

The plugin "move-addons" v1.3.8 exhibits a mixed security posture. On the positive side, the static analysis reveals robust security practices in several key areas. All identified AJAX handlers and REST API routes have proper authorization checks in place, and there are no shortcodes or cron events that could present an attack surface. Furthermore, the plugin exclusively uses prepared statements for its SQL queries and demonstrates a commitment to input sanitization with a significant portion of its outputs being properly escaped. However, there are notable areas of concern. A substantial 40% of outputs are not properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. The presence of two external HTTP requests, while not inherently dangerous, warrants closer inspection to ensure they are handled securely. The plugin's vulnerability history is a significant red flag, with a total of 8 known CVEs, all classified as medium severity. Although none are currently unpatched, this pattern of multiple medium-severity vulnerabilities, including Exposure of Sensitive Information, Cross-site Scripting, and Missing Authorization, suggests a recurring tendency for security flaws to emerge in the plugin. The most recent vulnerability being in late 2024 is particularly concerning given the current date.

Key Concerns

  • Significant percentage of unescaped outputs
  • History of 8 medium severity CVEs
  • Recent vulnerability in late 2024
  • Bundled library (DataTables) may be outdated
  • External HTTP requests present
Vulnerabilities
8

Move Addons for Elementor Security Vulnerabilities

CVEs by Year

8 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
8

8 total CVEs

CVE-2024-56254medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Move Addons for Elementor <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 30, 2024 Patched in 1.3.7 (10d)
CVE-2024-10360medium · 4.3Exposure of Sensitive Information to an Unauthorized Actor

Move Addons for Elementor <= 1.3.5 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates

Oct 28, 2024 Patched in 1.3.6 (1d)
CVE-2024-47364medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Move Addons for Elementor <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 30, 2024 Patched in 1.3.5 (11d)
CVE-2024-47396medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Move Addons for Elementor <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 25, 2024 Patched in 1.3.4 (8d)
CVE-2024-4695medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Move Addons for Elementor <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

May 20, 2024 Patched in 1.3.2 (1d)
CVE-2024-34562medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Move Addons for Elementor <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 7, 2024 Patched in 1.3.1 (9d)
CVE-2024-30525medium · 5.3Missing Authorization

Move Addons for Elementor <= 1.2.9 - Missing Authorization

Mar 29, 2024 Patched in 1.3.0 (6d)
CVE-2024-2131medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Move Addons for Elementor <= 1.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 22, 2024 Patched in 1.3.0 (11d)
Code Analysis
Analyzed Mar 16, 2026

Move Addons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
263
398 escaped
Nonce Checks
4
Capability Checks
5
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

DataTables

Output Escaping

60% escaped661 total outputs
Attack Surface

Move Addons for Elementor Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_htmove_save_opt_dataclasses\admin-dashboard.php:49
noprivwp_ajax_move_ajax_loginclasses\login-register-manager.php:44
authwp_ajax_htmove_addons_mailchimp_data_saveclasses\mailchimp.php:30
authwp_ajax_move_quickviewclasses\quick-view.php:35
noprivwp_ajax_move_quickviewclasses\quick-view.php:36
WordPress Hooks 18
actioninitbase\move-base.php:39
actionplugins_loadedbase\move-base.php:40
actionelementor/elements/categories_registeredbase\move-base.php:59
actiontemplate_redirectbase\move-base.php:75
actionwp_footerbase\move-base.php:78
actionadmin_menuclasses\admin-dashboard.php:48
actionadmin_enqueue_scriptsclasses\admin-dashboard.php:95
actionadmin_noticesclasses\admin-notices.php:38
actionadmin_noticesclasses\admin-notices.php:44
actionadmin_noticesclasses\admin-notices.php:50
actionwp_enqueue_scriptsclasses\assets.php:34
actionadmin_enqueue_scriptsclasses\assets.php:35
actionelementor/editor/after_enqueue_stylesclasses\assets.php:38
actionupdate_option_active_pluginsclasses\installer.php:48
actionelementor/initclasses\login-register-manager.php:34
actionmove_footer_contentclasses\quick-view.php:33
actionelementor/widgets/registerclasses\widgets-control.php:35
actionelementor/widgets/widgets_registeredclasses\widgets-control.php:37
Maintenance & Trust

Move Addons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version
Downloads62K

Community Trust

Rating80/100
Number of ratings6
Active installs3K
Developer Profile

Move Addons for Elementor Developer Profile

moveaddons

1 plugin · 3K total installs

98
trust score
Avg Security Score
97/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Move Addons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/move-addons/assets/admin/css/move-admin.css/wp-content/plugins/move-addons/assets/admin/js/move-admin.js
Version Parameters
move-addons/assets/admin/css/move-admin.css?ver=move-addons/assets/admin/js/move-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
htmove-admin-panelmove-dashboard
Data Attributes
data-tab
JS Globals
MOVE_ADDONS_ASSETS
FAQ

Frequently Asked Questions about Move Addons for Elementor