
UltraAddons for Elementor Security & Risk Analysis
wordpress.org/plugins/ultraaddons-elementor-liteFree widgets, Custom Fonts, Custom CSS, Anywhere Elementor Shortcode, Header & Footer Builder, Menu Builder, WooCommerce Widgets.
Is UltraAddons for Elementor Safe to Use in 2026?
High Risk
Score 44/100UltraAddons for Elementor carries significant security risk with 5 known CVEs, 3 still unpatched. Consider switching to a maintained alternative.
The "ultraaddons-elementor-lite" v2.0.2 plugin exhibits a mixed security posture. While the static analysis shows good practices like 100% prepared SQL statements and a high percentage of properly escaped output, several concerning areas exist. The presence of 3 shortcodes as entry points, even without immediate unprotected access, represents potential vectors for exploitation if not handled carefully within their logic. The static analysis also indicates file operations and external HTTP requests, which can introduce vulnerabilities if inputs influencing these operations are not rigorously sanitized. Furthermore, the plugin has a history of 5 known CVEs, with 3 remaining unpatched, all of medium severity. These include common and serious vulnerabilities like Cross-site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Authorization Bypass. The recency of the last vulnerability (2025-05-16) suggests ongoing security issues. While the current version's static analysis highlights some positive security implementations, the historical prevalence and unpatched nature of past vulnerabilities significantly elevate the risk, suggesting a pattern of recurring security weaknesses that require careful attention and prompt patching.
Key Concerns
- Unpatched CVEs
- Medium severity CVEs
- File operations present
- External HTTP requests present
- Shortcodes as entry points
UltraAddons for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
UltraAddons Elementor Lite <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
UltraAddons <= 2.0.0 - Cross-Site Request Forgery
UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) <= 1.1.8 - Insecure Direct Object Reference to Sensitive Information Exposure via UA_Template Shortcode
UltraAddons Elementor Lite <= 2.0.0 - Authenticated (Author+) Stored Cross-Site Scripting
UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
UltraAddons for Elementor Code Analysis
Bundled Libraries
Output Escaping
UltraAddons for Elementor Attack Surface
Shortcodes 3
WordPress Hooks 91
Maintenance & Trust
UltraAddons for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
UltraAddons for Elementor Alternatives
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder
templatespare
Imagine this... You’re planning your new website. You’re excited at first—but then reality hits. The design takes months. You wait for the developer t …
DragDropr – Visual Drag & Drop Page Builder
dragdropr
DragDropr is a What-You-See-Is-What-You-REALLY-Get visual editor.
Multi-step Forms FREE (for Elementor)
multi-step-forms-free-for-elementor
A simple plugin that streamlines the creation of multistep (or multiple page) forms to an easy drag-and-drop through the power of Elementor Pro.
Page builder for Posts – Mong9 Editor
mong9-editor
The most advanced frontend drag & drop content editor. Mong9 Editor is a responsive page builder which can be used to extend the Classic Editor.
UltraAddons for Elementor Developer Profile
12 plugins · 20K total installs
How We Detect UltraAddons for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ultraaddons-elementor-lite/assets/css/ultraaddons-admin.css/wp-content/plugins/ultraaddons-elementor-lite/assets/css/ultraaddons-public.css/wp-content/plugins/ultraaddons-elementor-lite/assets/js/ultraaddons-public.jsultraaddons-elementor-lite/assets/css/ultraaddons-admin.css?ver=ultraaddons-elementor-lite/assets/css/ultraaddons-public.css?ver=ultraaddons-elementor-lite/assets/js/ultraaddons-public.js?ver=HTML / DOM Fingerprints
ultraaddons-elementor-litedata-ua-widget-idultraaddons_addons_switchers