Flipbox Addon for Elementor Security & Risk Analysis

wordpress.org/plugins/ultimate-flipbox-addon-for-elementor

Flip Boxes for Elementor – animated, 3D, responsive flip box widgets for posts, custom post types, portfolios, and product showcases.

300 active installs v2.1.2 PHP 7.0+ WP 5.0+ Updated Apr 13, 2026
elementor-flipboxflip-boxflip-box-widgetflip-boxesflipbox
98
A · Safe
CVEs total2
Unpatched0
Last CVEApr 17, 2026
Safety Verdict

Is Flipbox Addon for Elementor Safe to Use in 2026?

Generally Safe

Score 98/100

Flipbox Addon for Elementor has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Apr 17, 2026Updated 1mo ago
Risk Assessment

The ultimate-flipbox-addon-for-elementor plugin v2.0.8 exhibits a generally strong security posture, with a low number of entry points and robust implementation of security best practices. The static analysis shows no dangerous functions, all SQL queries are prepared, and a very high percentage of output is properly escaped. Nonce and capability checks are present on all identified AJAX handlers, and there are no unhandled taint flows or unsanitized paths. This indicates a proactive approach to secure coding and input validation within the plugin's codebase.

However, the plugin does make two external HTTP requests, which can be a potential vector for vulnerabilities if the remote endpoints are compromised or if the requests are not handled securely. While the vulnerability history shows only one medium-severity CVE in the past, its recency (November 2024) and the common vulnerability type of Cross-Site Scripting (XSS) warrant continued vigilance. The fact that this CVE is currently patched is positive, but it highlights the potential for XSS to be introduced in this type of plugin.

In conclusion, the plugin is well-developed from a security perspective, demonstrating good practices in critical areas like SQL and output escaping. The primary areas for attention are the external HTTP requests and the awareness of past XSS vulnerabilities, which, while patched, suggest a type of vulnerability that can be easily introduced if input handling isn't meticulously maintained.

Key Concerns

  • External HTTP requests present
  • Past medium severity CVE (XSS)
Vulnerabilities
2 published

Flipbox Addon for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-6048medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Flipbox Addon for Elementor <= 2.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Attributes

Apr 17, 2026 Patched in 2.1.2 (1d)
CVE-2024-51870medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Ultimate Flipbox Addon for Elementor 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 8, 2024 Patched in 1.0.5 (46d)
Version History

Flipbox Addon for Elementor Release Timeline

v2.1.2Current
v2.1.11 CVE
v2.1.01 CVE
v2.0.81 CVE
v2.0.71 CVE
v2.0.61 CVE
v2.0.51 CVE
v2.0.41 CVE
v2.0.31 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.0.61 CVE
v1.0.51 CVE
Code Analysis
Analyzed Mar 16, 2026

Flipbox Addon for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
368 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

97% escaped378 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
ufae_preset_styles (includes\class-ufae-ajax-handler.php:52)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Flipbox Addon for Elementor Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_ufae_send_feedbackadmin\feedback\class-ufae-feedback-form.php:76
authwp_ajax_ufae_review_dismissadmin\review\class-ufae-review-form.php:40
authwp_ajax_ufae_preset_stylesincludes\class-ufae-ajax-handler.php:43
WordPress Hooks 13
actionadmin_enqueue_scriptsadmin\feedback\class-ufae-feedback-form.php:77
actionadmin_headadmin\feedback\class-ufae-feedback-form.php:78
actionadmin_noticesadmin\review\class-ufae-review-form.php:38
actionadmin_enqueue_scriptsadmin\review\class-ufae-review-form.php:39
actionelementor/widgets/registerincludes\class-ufae-register.php:48
actionelementor/initincludes\class-ufae-register.php:49
actionelementor/controls/registerincludes\class-ufae-register.php:50
actionplugins_loadedultimate-flipbox-addon-for-elementor.php:79
actionadmin_initultimate-flipbox-addon-for-elementor.php:80
actionadmin_noticesultimate-flipbox-addon-for-elementor.php:175
actionelementor/frontend/after_enqueue_scriptswidget\post\class-ufae-post-widget.php:41
actionelementor/frontend/after_enqueue_scriptswidget\simple\class-ufae-simple-widget.php:48
actionelementor/frontend/after_enqueue_scriptswidget\stories\class-ufae-stories-widget.php:50
Maintenance & Trust

Flipbox Addon for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 13, 2026
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs300
Developer Profile

Flipbox Addon for Elementor Developer Profile

dragwyb

2 plugins · 300 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
24 days
View full developer profile
Detection Fingerprints

How We Detect Flipbox Addon for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-flipbox-addon-for-elementor/admin/controls/assets/css/ufae-control.min.css
Version Parameters
ultimate-flipbox-addon-for-elementor/admin/controls/assets/css/ufae-control.min.css?ver=ultimate-flipbox-addon-for-elementor/assets/css/ufae-frontend.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
ufae-flipbox-itemufae-flipbox-wrap
Data Attributes
data-animationdata-effectdata-duration
JS Globals
UFAE
FAQ

Frequently Asked Questions about Flipbox Addon for Elementor