WPMozo Addons Lite for Elementor Security & Risk Analysis

wordpress.org/plugins/wpmozo-addons-lite-for-elementor

WPMozo Addons Lite for Elementor is a plugin that adds new design and functional widgets to Elementor.

200 active installs v1.8.2 PHP 5.6+ WP 5.3+ Updated Jan 9, 2026
addonselementorelementor-addonelementor-extensionpage-builder
98
A · Safe
CVEs total2
Unpatched0
Last CVEJan 3, 2025
Safety Verdict

Is WPMozo Addons Lite for Elementor Safe to Use in 2026?

Generally Safe

Score 98/100

WPMozo Addons Lite for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jan 3, 2025Updated 2mo ago
Risk Assessment

The "wpmozo-addons-lite-for-elementor" plugin v1.8.2 exhibits a mixed security posture. While it demonstrates good practices in handling SQL queries with prepared statements and a high percentage of properly escaped output, significant concerns arise from its attack surface. A notable 7 AJAX handlers are exposed without any authentication checks, presenting a direct avenue for attackers to interact with plugin functionalities without proper authorization. The absence of taint analysis results for this version is also a point of concern, as it limits a deeper understanding of potential data manipulation vulnerabilities. The plugin's vulnerability history reveals a pattern of common and critical vulnerability types, including PHP Remote File Inclusion and Cross-site Scripting, with a recent high-severity vulnerability in 2025. While no vulnerabilities are currently unpatched, the historical prevalence of these issues suggests potential underlying coding practices that warrant careful attention and ongoing vigilance. The plugin's strengths lie in its SQL handling and output escaping, but these are overshadowed by the critical lack of authentication on a substantial portion of its attack surface and its history of severe vulnerabilities.

Key Concerns

  • 7 AJAX handlers without auth checks
  • Previous high severity vulnerability
  • Previous medium severity vulnerability
  • Vulnerability history includes RFI
  • Vulnerability history includes XSS
  • Bundled outdated library: Select2
Vulnerabilities
2

WPMozo Addons Lite for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2024-56282high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

WPMozo Addons Lite for Elementor <= 1.1.0 - Authenticated (Contributor+) Local File Inclusion

Jan 3, 2025 Patched in 1.1.1 (6d)
CVE-2024-56221medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WPMozo Addons Lite for Elementor <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 19, 2024 Patched in 1.3.0 (21d)
Code Analysis
Analyzed Mar 16, 2026

WPMozo Addons Lite for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
1215 escaped
Nonce Checks
4
Capability Checks
3
File Operations
3
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

98% escaped1244 total outputs
Attack Surface
7 unprotected

WPMozo Addons Lite for Elementor Attack Surface

Entry Points7
Unprotected7

AJAX Handlers 7

authwp_ajax_wpmozo_ae_lite_panel_save_settingsincludes\class-wpmozo-addons-lite-for-elementor.php:183
authwp_ajax_wpmozo_get_testimonialsincludes\class-wpmozo-addons-lite-for-elementor.php:216
noprivwp_ajax_wpmozo_get_testimonialsincludes\class-wpmozo-addons-lite-for-elementor.php:217
authwp_ajax_wpmozo_ae_select2_search_postincludes\class-wpmozo-addons-lite-for-elementor.php:218
noprivwp_ajax_wpmozo_ae_select2_search_postincludes\class-wpmozo-addons-lite-for-elementor.php:219
authwp_ajax_wpmozo_ae_select2_get_titleincludes\class-wpmozo-addons-lite-for-elementor.php:220
noprivwp_ajax_wpmozo_ae_select2_get_titleincludes\class-wpmozo-addons-lite-for-elementor.php:221
WordPress Hooks 20
actionplugins_loadedincludes\class-wpmozo-addons-lite-for-elementor.php:159
actionwp_loadedincludes\class-wpmozo-addons-lite-for-elementor.php:176
actionadmin_menuincludes\class-wpmozo-addons-lite-for-elementor.php:179
actionsave_postincludes\class-wpmozo-addons-lite-for-elementor.php:180
actionadmin_enqueue_scriptsincludes\class-wpmozo-addons-lite-for-elementor.php:181
actionadmin_enqueue_scriptsincludes\class-wpmozo-addons-lite-for-elementor.php:182
actionadd_meta_boxesincludes\class-wpmozo-addons-lite-for-elementor.php:186
actionsave_postincludes\class-wpmozo-addons-lite-for-elementor.php:188
actionadd_meta_boxesincludes\class-wpmozo-addons-lite-for-elementor.php:192
actionsave_postincludes\class-wpmozo-addons-lite-for-elementor.php:194
actionelementor/initincludes\class-wpmozo-addons-lite-for-elementor.php:209
actionelementor/elements/categories_registeredincludes\class-wpmozo-addons-lite-for-elementor.php:210
actionelementor/widgets/registerincludes\class-wpmozo-addons-lite-for-elementor.php:211
actionelementor/frontend/after_register_stylesincludes\class-wpmozo-addons-lite-for-elementor.php:212
actionelementor/frontend/after_register_scriptsincludes\class-wpmozo-addons-lite-for-elementor.php:213
actionelementor/editor/before_enqueue_scriptsincludes\class-wpmozo-addons-lite-for-elementor.php:214
actionelementor/controls/controls_registeredincludes\class-wpmozo-addons-lite-for-elementor.php:215
actionadmin_noticeswpmozo-addons-lite-for-elementor.php:37
actionadmin_noticeswpmozo-addons-lite-for-elementor.php:76
actioninitwpmozo-addons-lite-for-elementor.php:134
Maintenance & Trust

WPMozo Addons Lite for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 9, 2026
PHP min version5.6
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

WPMozo Addons Lite for Elementor Developer Profile

Elicus

5 plugins · 410 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect WPMozo Addons Lite for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpmozo-addons-lite-for-elementor/assets/css/wpmozo-addons-lite.css/wp-content/plugins/wpmozo-addons-lite-for-elementor/assets/js/wpmozo-addons-lite.js/wp-content/plugins/wpmozo-addons-lite-for-elementor/assets/js/frontend.js
Script Paths
/wp-content/plugins/wpmozo-addons-lite-for-elementor/assets/js/wpmozo-addons-lite.js/wp-content/plugins/wpmozo-addons-lite-for-elementor/assets/js/frontend.js
Version Parameters
/wp-content/plugins/wpmozo-addons-lite-for-elementor/assets/css/wpmozo-addons-lite.css?ver=/wp-content/plugins/wpmozo-addons-lite-for-elementor/assets/js/wpmozo-addons-lite.js?ver=/wp-content/plugins/wpmozo-addons-lite-for-elementor/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpmozo-addons-lite-for-elementor
JS Globals
WPMozoLiteFrontend
FAQ

Frequently Asked Questions about WPMozo Addons Lite for Elementor