RS Elements Elementor Addon Security & Risk Analysis

wordpress.org/plugins/rselements-lite

RSElements Addon is a collection of powerful widgets that works perfectly with Elementor page builder. It has 30+ widgets so you can eaily make awesom …

500 active installs v1.1.5 PHP + WP 4.7+ Updated Dec 19, 2024
elementorelementor-addonelementor-widgetelementsessential-widget
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 10, 2025
Safety Verdict

Is RS Elements Elementor Addon Safe to Use in 2026?

Mostly Safe

Score 70/100

RS Elements Elementor Addon is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 10, 2025Updated 1yr ago
Risk Assessment

The rselements-lite plugin version 1.1.5 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries are prepared, and the vast majority of output is properly escaped. File operations and external HTTP requests are also absent, reducing potential attack vectors. However, the complete absence of AJAX handlers, REST API routes, shortcodes, and cron events as entry points is unusual and could indicate a lack of functionality that typically interfaces with user input. While taint analysis shows no identified unsanitized paths, the zero flows analyzed is a concern, suggesting either no flows were detectable or the analysis was incomplete.

The plugin's vulnerability history is a significant concern. It has a known, currently unpatched medium-severity CVE related to Cross-Site Scripting (XSS). The fact that the last vulnerability was recorded in April 2025 suggests a recent exposure, and the presence of an unpatched issue poses a direct and immediate risk. The consistent pattern of XSS vulnerabilities in the past, even if this is the only one listed, points to a potential weakness in how the plugin handles user-provided data when rendering output.

In conclusion, while rselements-lite v1.1.5 demonstrates good practices in secure coding concerning SQL and output escaping, the unpatched XSS vulnerability is a critical risk that overshadows these strengths. The lack of identified entry points in the static analysis warrants further investigation to understand the plugin's full functionality and potential hidden attack surfaces. The current unpatched CVE makes this plugin a medium-risk component, and immediate patching is highly recommended.

Key Concerns

  • Unpatched CVE (Medium Severity)
  • Zero Taint Flows Analyzed
  • Zero Nonce Checks
Vulnerabilities
1

RS Elements Elementor Addon Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-26745medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

RS Elements Elementor Addon <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 10, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

RS Elements Elementor Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
1214 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped1237 total outputs
Attack Surface

RS Elements Elementor Addon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 26
actioninitbase.php:79
actionplugins_loadedbase.php:80
actionadmin_noticesbase.php:115
actionadmin_noticesbase.php:121
actionadmin_noticesbase.php:127
actionelementor/widgets/registerbase.php:132
actionelementor/elements/categories_registeredbase.php:133
actionwp_enqueue_scriptsbase.php:134
actionadmin_enqueue_scriptsbase.php:135
actionelementor/editor/before_enqueue_scriptsbase.php:136
actionwp_enqueue_scriptsbase.php:138
actionelementor/elements/categories_registeredbase.php:374
actioninitpost-type\portfolio\portfolio.php:15
actioninitpost-type\portfolio\portfolio.php:16
actionadmin_menupost-type\portfolio\portfolio.php:17
actionsave_postpost-type\portfolio\portfolio.php:18
actioninitpost-type\team\team.php:43
actioninitpost-type\team\team.php:57
actionrestrict_manage_postspost-type\team\team.php:83
actionadd_meta_boxespost-type\team\team.php:94
actionadd_meta_boxespost-type\team\team.php:129
actionsave_postpost-type\team\team.php:182
actioninitpost-type\testimonial\testimonial.php:4
actioninitpost-type\testimonial\testimonial.php:5
actionadmin_menupost-type\testimonial\testimonial.php:6
actionsave_postpost-type\testimonial\testimonial.php:7
Maintenance & Trust

RS Elements Elementor Addon Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 19, 2024
PHP min version
Downloads12K

Community Trust

Rating70/100
Number of ratings4
Active installs500
Developer Profile

RS Elements Elementor Addon Developer Profile

RSTheme

9 plugins · 15K total installs

97
trust score
Avg Security Score
96/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect RS Elements Elementor Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rselements-lite/assets/css/bootstrap.min.css/wp-content/plugins/rselements-lite/assets/css/magnific-popup.css/wp-content/plugins/rselements-lite/assets/css/fontawesome.css/wp-content/plugins/rselements-lite/assets/css/brands.css/wp-content/plugins/rselements-lite/assets/css/solid.css/wp-content/plugins/rselements-lite/assets/fonts/flaticon.css/wp-content/plugins/rselements-lite/assets/css/headding-title.css/wp-content/plugins/rselements-lite/assets/css/rsaddons.css+9 more
Script Paths
/wp-content/plugins/rselements-lite/assets/js/jquery.magnific-popup.min.js/wp-content/plugins/rselements-lite/assets/js/popper.min.js/wp-content/plugins/rselements-lite/assets/js/bootstrap.min.js/wp-content/plugins/rselements-lite/assets/js/waypoints.min.js/wp-content/plugins/rselements-lite/assets/js/jquery.counterup.min.js/wp-content/plugins/rselements-lite/assets/js/headding-title.js+1 more
Version Parameters
/wp-content/plugins/rselements-lite/assets/css/bootstrap.min.css?ver=/wp-content/plugins/rselements-lite/assets/css/magnific-popup.css?ver=/wp-content/plugins/rselements-lite/assets/css/fontawesome.css?ver=/wp-content/plugins/rselements-lite/assets/css/brands.css?ver=/wp-content/plugins/rselements-lite/assets/css/solid.css?ver=/wp-content/plugins/rselements-lite/assets/fonts/flaticon.css?ver=/wp-content/plugins/rselements-lite/assets/css/headding-title.css?ver=/wp-content/plugins/rselements-lite/assets/css/rsaddons.css?ver=/wp-content/plugins/rselements-lite/assets/js/jquery.magnific-popup.min.js?ver=/wp-content/plugins/rselements-lite/assets/js/popper.min.js?ver=/wp-content/plugins/rselements-lite/assets/js/bootstrap.min.js?ver=/wp-content/plugins/rselements-lite/assets/js/waypoints.min.js?ver=/wp-content/plugins/rselements-lite/assets/js/jquery.counterup.min.js?ver=/wp-content/plugins/rselements-lite/assets/js/headding-title.js?ver=/wp-content/plugins/rselements-lite/assets/js/custom.js?ver=/wp-content/plugins/rselements-lite/assets/css/admin/admin.css?ver=/wp-content/plugins/rselements-lite/assets/fonts/flaticon.css?ver=/wp-content/plugins/rselements-lite/assets/css/admin/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
rsaddon_category
HTML Comments
Plugin Name: RSElements LiteDescription: <a href="https://rstheme.com/products/wordpress/plugins/elementor/">RS Elementor Addon</a> is the most advanced frontend drag & drop page builder addon. Create high-end, pixel perfect websites at record speeds. Any theme, any page, any design as like you want.Plugin URI: https://rstheme.com/Version: 1.1.5+32 more
Data Attributes
data-elementor-iddata-elementor-type
JS Globals
RS_ADDON_GLOBAL_SETTINGS
FAQ

Frequently Asked Questions about RS Elements Elementor Addon