X Addons for Elementor Security & Risk Analysis

wordpress.org/plugins/x-addons-elementor

X Addons - A powerful collection of creative and lightweight Elementor widgets that help you design beautiful websites faster and easier.

800 active installs v1.0.23 PHP 7.4+ WP 5.8+ Updated Dec 6, 2025
addonselementorelementor-addonselementor-widgetswidgets
52
C · Use Caution
CVEs total4
Unpatched2
Last CVEJan 14, 2026
Safety Verdict

Is X Addons for Elementor Safe to Use in 2026?

Use With Caution

Score 52/100

X Addons for Elementor has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.

4 known CVEs 2 unpatched Last CVE: Jan 14, 2026Updated 5mo ago
Risk Assessment

The static analysis of x-addons-elementor v1.0.23 reveals a strong adherence to secure coding practices in its immediate implementation. The absence of identified dangerous functions, file operations, external HTTP requests, and the exclusive use of prepared statements for SQL queries are positive indicators. Furthermore, the high percentage of properly escaped output suggests a good effort to mitigate cross-site scripting vulnerabilities within the directly analyzed code. However, the complete lack of entry points like AJAX handlers, REST API routes, shortcodes, and cron events in the static analysis is unusual and might indicate these features are handled elsewhere or that the analysis scope was limited.

The primary concern stems from the plugin's vulnerability history. With a total of 4 known CVEs, and 2 of them currently unpatched, this plugin presents a significant risk. The common vulnerability types being Missing Authorization and Cross-site Scripting, coupled with the medium severity of these historical issues, directly contradict the positive findings in the static analysis, suggesting past code may have been vulnerable or that current analysis missed critical aspects. The recency of the last vulnerability (2026-01-14) is also concerning and likely a typo or futuristic projection, indicating ongoing issues.

In conclusion, while the current version's static code exhibits good security hygiene in specific areas, the persistent history of unpatched vulnerabilities, particularly those related to authorization and XSS, overshadows these strengths. The presence of unpatched CVEs means active exploitation is possible. The plugin's reliance on potentially vulnerable historical code or areas not covered by static analysis warrants extreme caution. Users should prioritize updating to a version that has addressed all past CVEs.

Key Concerns

  • Unpatched CVEs
  • Missing Nonce Checks
  • Missing Capability Checks
  • Unusual lack of identified entry points in static analysis
Vulnerabilities
4 published

X Addons for Elementor Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
2 CVEs in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2026-24605medium · 4.3Missing Authorization

X Addons for Elementor <= 1.0.23 - Missing Authorization

Jan 14, 2026Unpatched
CVE-2026-22518medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

X Addons for Elementor <= 1.0.23 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 7, 2026Unpatched
CVE-2025-9204medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

X Addons for Elementor <= 1.0.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Video ID Field

Oct 2, 2025 Patched in 1.0.17 (8d)
CVE-2025-48132medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

X Addons for Elementor <= 1.0.16 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 16, 2025 Patched in 1.0.17 (155d)
Code Analysis
Analyzed Mar 16, 2026

X Addons for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
244 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped255 total outputs
Attack Surface

X Addons for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionelementor/elements/categories_registeredincludes\plugin.php:21
actionelementor/initincludes\plugin.php:91
actionadmin_noticesincludes\plugin.php:108
actionadmin_noticesincludes\plugin.php:114
actionadmin_noticesincludes\plugin.php:120
actionelementor/widgets/registerincludes\plugin.php:222
actionplugins_loadedx-addons-elementor.php:35
actionwp_enqueue_scriptsx-addons-elementor.php:50
Maintenance & Trust

X Addons for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 6, 2025
PHP min version7.4
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs800
Developer Profile

X Addons for Elementor Developer Profile

pencilwp

2 plugins · 800 total installs

71
trust score
Avg Security Score
76/100
Avg Patch Time
82 days
View full developer profile
Detection Fingerprints

How We Detect X Addons for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/x-addons-elementor/assets/css/slick.css/wp-content/plugins/x-addons-elementor/assets/css/fancy-box.css/wp-content/plugins/x-addons-elementor/assets/css/odometer.css/wp-content/plugins/x-addons-elementor/assets/css/xa-styles.css/wp-content/plugins/x-addons-elementor/assets/js/slick.js/wp-content/plugins/x-addons-elementor/assets/js/odometer.js/wp-content/plugins/x-addons-elementor/assets/js/circle-progress.js/wp-content/plugins/x-addons-elementor/assets/js/fancy-box.js+2 more
Script Paths
/wp-content/plugins/x-addons-elementor/assets/js/slick.js/wp-content/plugins/x-addons-elementor/assets/js/odometer.js/wp-content/plugins/x-addons-elementor/assets/js/circle-progress.js/wp-content/plugins/x-addons-elementor/assets/js/fancy-box.js/wp-content/plugins/x-addons-elementor/assets/js/typed.js/wp-content/plugins/x-addons-elementor/assets/js/plugin-active.js
Version Parameters
x-addons-elementor/assets/css/slick.css?ver=1.0x-addons-elementor/assets/css/fancy-box.css?ver=3.5.7x-addons-elementor/assets/css/odometer.css?ver=1.0x-addons-elementor/assets/css/xa-styles.css?ver=1.0x-addons-elementor/assets/js/slick.js?ver=2.0x-addons-elementor/assets/js/odometer.js?ver=1.0x-addons-elementor/assets/js/circle-progress.js?ver=1.2.2x-addons-elementor/assets/js/fancy-box.js?ver=3.5.7x-addons-elementor/assets/js/typed.js?ver=1.0x-addons-elementor/assets/js/plugin-active.js?ver=1.0

HTML / DOM Fingerprints

CSS Classes
xa-slider-wrap
JS Globals
XEA_Ajax_Url
FAQ

Frequently Asked Questions about X Addons for Elementor