WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Security & Risk Analysis

wordpress.org/plugins/wpb-elementor-addons

A powerful collection of custom Elementor widgets and extensions to build advanced layouts with ease.

3K active installs v1.7 PHP 8.3+ WP 5.0+ Updated Mar 13, 2026
addonselementorelementor-addonselementor-elementselementor-widget
74
B · Generally Safe
CVEs total4
Unpatched1
Last CVESep 5, 2025
Safety Verdict

Is WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Safe to Use in 2026?

Mostly Safe

Score 74/100

WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More is generally safe to use. 4 past CVEs were resolved. Keep it updated.

4 known CVEs 1 unpatched Last CVE: Sep 5, 2025Updated 22d ago
Risk Assessment

The "wpb-elementor-addons" v1.7 plugin exhibits a mixed security posture. On one hand, the static analysis reveals strong adherence to secure coding practices in several areas. The complete absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The high percentage of properly escaped output (92%) and the presence of a nonce check are also positive indicators, suggesting an effort to mitigate common vulnerabilities.

However, significant concerns arise from the plugin's vulnerability history and the lack of certain security checks. The fact that there are four known CVEs, with one currently unpatched, and all historically being medium severity Cross-Site Scripting (XSS) vulnerabilities, points to a recurring pattern of input sanitization issues. While no critical taint flows were detected in the current static analysis, the historical data suggests this is a persistent risk that has not been fully eradicated. The absence of capability checks on any entry points is also a notable weakness, as it means that even if entry points were discovered, they might not be properly restricted to authorized users.

In conclusion, while "wpb-elementor-addons" v1.7 demonstrates strengths in its secure coding implementation for certain aspects, the ongoing presence of unpatched vulnerabilities, particularly XSS, and the lack of capability checks present a significant risk. The developer needs to address the historical XSS issues comprehensively and ensure robust authorization checks are in place for all potential entry points in future releases. The current state is not ideal and requires attention to move towards a more secure posture.

Key Concerns

  • Currently unpatched CVEs
  • Medium severity CVE history
  • Lack of capability checks
  • Unescaped output (8% of outputs)
Vulnerabilities
4

WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Security Vulnerabilities

CVEs by Year

3 CVEs in 2024
2024
1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2025-58793medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WPB Elementor Addons <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 5, 2025Unpatched
CVE-2024-3063medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WPB Elementor Addons <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 29, 2024 Patched in 1.2 (2d)
CVE-2024-4896medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WPB Elementor Addons <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via url Parameter

May 21, 2024 Patched in 1.2 (1d)
CVE-2024-34791medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WPB Elementor Addons <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 17, 2024 Patched in 1.2 (13d)
Code Analysis
Analyzed Mar 16, 2026

WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
292 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped318 total outputs
Attack Surface

WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actionadmin_menuadmin\admin-page.php:6
actionadmin_enqueue_scriptsadmin\class.settings-api.php:35
actionadmin_initadmin\plugin-settings.php:25
actionadmin_menuadmin\plugin-settings.php:26
filterwpb_ea_required_addonsinc\wpb_functions.php:54
filterwpb_ea_pro_required_addoninc\wpb_functions.php:79
actionelementor/elements/categories_registeredinc\wpb_functions.php:214
actionelementor/widgets/registerinc\wpb_functions.php:235
filterbody_classinc\wpb_functions.php:395
filterelementor/icons_manager/additional_tabsinc\wpb_functions.php:409
actionwp_enqueue_scriptsinc\wpb_scripts.php:31
actionadmin_enqueue_scriptsinc\wpb_scripts.php:49
actionelementor/frontend/after_register_stylesinc\wpb_scripts.php:56
actionelementor/preview/enqueue_stylesinc\wpb_scripts.php:66
actionelementor/frontend/after_register_scriptsinc\wpb_scripts.php:76
actionwp_enqueue_scriptsinc\wpb_scripts.php:115
actionplugins_loadedmain.php:78
actionadmin_noticesmain.php:80
actionadmin_noticesmain.php:108
actionadmin_initmain.php:109
actionactivated_pluginmain.php:110
Maintenance & Trust

WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version8.3
Downloads95K

Community Trust

Rating76/100
Number of ratings11
Active installs3K
Developer Profile

WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More Developer Profile

WPBean

25 plugins · 40K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
20 days
View full developer profile
Detection Fingerprints

How We Detect WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpb-elementor-addons/assets/css/wpb-elementor-addons.css/wp-content/plugins/wpb-elementor-addons/assets/js/wpb-elementor-addons.js
Script Paths
/wp-content/plugins/wpb-elementor-addons/assets/js/wpb-elementor-addons.js
Version Parameters
wpb-elementor-addons/assets/css/wpb-elementor-addons.css?ver=wpb-elementor-addons/assets/js/wpb-elementor-addons.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpb-ea-discount-notice
Data Attributes
data-wpb-ea-editordata-wpb-ea-editor-content
JS Globals
WPB_EA_LOCALIZEwpb_ea_params
FAQ

Frequently Asked Questions about WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More