WPZOOM Addons for Beaver Builder Security & Risk Analysis

wordpress.org/plugins/wpzoom-addons-for-beaver-builder

A suite of useful addons for Beaver Builder for WPZOOM themes.

4K active installs v1.3.8 PHP 7.4+ WP 6.0+ Updated Jan 15, 2026
addonsbeaver-builderinspiropage-builderwpzoom
96
A · Safe
CVEs total6
Unpatched0
Last CVEJul 1, 2024
Safety Verdict

Is WPZOOM Addons for Beaver Builder Safe to Use in 2026?

Generally Safe

Score 96/100

WPZOOM Addons for Beaver Builder has a strong security track record. Known vulnerabilities have been patched promptly.

6 known CVEsLast CVE: Jul 1, 2024Updated 2mo ago
Risk Assessment

The plugin "wpzoom-addons-for-beaver-builder" version 1.3.8 exhibits a mixed security posture. On one hand, the static analysis shows a very small attack surface with no apparent unprotected entry points, excellent use of prepared statements for SQL queries, and a reasonable number of file operations and external HTTP requests. The presence of nonce checks and a single capability check, while limited, are positive signs. However, a significant concern arises from the very low percentage of properly escaped output (12%). This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into user views.

The vulnerability history is a major red flag, with a total of 6 known CVEs, including 1 high and 5 medium severity vulnerabilities. The common types of vulnerabilities, specifically Remote File Inclusion and Cross-Site Scripting, align with the output escaping concerns identified in the static analysis. While there are currently no unpatched CVEs, the historical pattern of these specific vulnerability types is worrying and indicates a recurring weakness in how user-supplied data is handled. The most recent vulnerability was identified on July 1st, 2024, suggesting that despite past fixes, the underlying issues may not be fully eradicated.

In conclusion, while the plugin demonstrates some good security practices like prepared statements and a limited attack surface, the critically low output escaping percentage and the history of XSS and RFI vulnerabilities present substantial risks. The plugin requires immediate attention to address the widespread output escaping deficiencies and a thorough review to ensure past vulnerability patterns are truly resolved.

Key Concerns

  • Low percentage of properly escaped output (12%)
  • History of 1 high severity vulnerability
  • History of 5 medium severity vulnerabilities
  • Common vulnerability type: Cross-site Scripting
  • Common vulnerability type: Remote File Inclusion
  • Only 1 capability check observed
Vulnerabilities
6

WPZOOM Addons for Beaver Builder Security Vulnerabilities

CVEs by Year

6 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1
Medium
5

6 total CVEs

CVE-2024-37464high · 7.2Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Beaver Builder Addons by WPZOOM <= 1.3.5 - Authenticated (Editor+) Local File Inclusion

Jul 1, 2024 Patched in 1.3.6 (9d)
CVE-2024-2187medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Beaver Builder Addons by WPZOOM <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget

Mar 13, 2024 Patched in 1.3.5 (28d)
CVE-2024-2185medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Beaver Builder Addons by WPZOOM <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box Widget

Mar 13, 2024 Patched in 1.3.5 (248d)
CVE-2024-2181medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Beaver Builder Addons by WPZOOM <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget

Mar 13, 2024 Patched in 1.3.5 (28d)
CVE-2024-2186medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Beaver Builder Addons by WPZOOM <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Members Widget

Mar 13, 2024 Patched in 1.3.5 (28d)
CVE-2024-2183medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Beaver Builder Addons by WPZOOM <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading Widget

Mar 13, 2024 Patched in 1.3.5 (28d)
Code Analysis
Analyzed Mar 16, 2026

WPZOOM Addons for Beaver Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
995
132 escaped
Nonce Checks
1
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

12% escaped1127 total outputs
Attack Surface

WPZOOM Addons for Beaver Builder Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wpzabb_slideshow_get_thumbmodules\wpzabb-slideshow\wpzabb-slideshow.php:51
WordPress Hooks 19
filterfl_builder_render_cssclasses\class-ui-panel.php:17
filterfl_builder_render_jsclasses\class-ui-panel.php:18
filterattachment_fields_to_editclasses\class-wpzabb-attachment.php:16
filterattachment_fields_to_saveclasses\class-wpzabb-attachment.php:17
filterfl_builder_register_settings_formclasses\class-wpzabb-helper.php:18
filterfl_builder_settings_form_defaultsclasses\class-wpzabb-init.php:26
actioninitclasses\class-wpzabb-init.php:29
actionwp_enqueue_scriptsclasses\class-wpzabb-init.php:32
actionadmin_noticesclasses\class-wpzabb-init.php:44
actionnetwork_admin_noticesclasses\class-wpzabb-init.php:45
actionplugins_loadedclasses\class-wpzabb-init.php:185
filterfl_builder_layout_datamodules\wpzabb-button\wpzabb-button.php:30
filterwpzabb_food_menu_price_unitsmodules\wpzabb-food-menu\wpzabb-food-menu.php:32
filtersharing_enqueue_scriptsmodules\wpzabb-posts\wpzabb-posts.php:45
filterexcerpt_lengthmodules\wpzabb-posts\wpzabb-posts.php:248
actionfl_builder_loop_settings_after_formmodules\wpzabb-slideshow\wpzabb-slideshow.php:47
filterfl_builder_loop_query_argsmodules\wpzabb-slideshow\wpzabb-slideshow.php:48
actionadmin_noticeswpzoom-bb-addon-pack.php:104
actionnetwork_admin_noticeswpzoom-bb-addon-pack.php:105
Maintenance & Trust

WPZOOM Addons for Beaver Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 15, 2026
PHP min version7.4
Downloads75K

Community Trust

Rating100/100
Number of ratings2
Active installs4K
Developer Profile

WPZOOM Addons for Beaver Builder Developer Profile

WPZOOM

24 plugins · 337K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
102 days
View full developer profile
Detection Fingerprints

How We Detect WPZOOM Addons for Beaver Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpzoom-addons-for-beaver-builder/assets/css/magnific-popup.css/wp-content/plugins/wpzoom-addons-for-beaver-builder/assets/js/jquery.magnific-popup.min.js
Script Paths
/wp-content/plugins/wpzoom-addons-for-beaver-builder/assets/js/jquery.magnific-popup.min.js
Version Parameters
wpzoom-addons-for-beaver-builder/assets/css/magnific-popup.css?ver=wpzoom-addons-for-beaver-builder/assets/js/jquery.magnific-popup.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpzabb-ui-panel-wrapper
Data Attributes
data-wpzabb-ui-panel
JS Globals
wpzabb_global_settings
FAQ

Frequently Asked Questions about WPZOOM Addons for Beaver Builder