XLTab – Accordions and Tabs for Elementor Page Builder Security & Risk Analysis

wordpress.org/plugins/xl-tab

The XLTab plugin you install after Elementor! and enjoy ultimate tab accordion.

1K active installs v1.5 PHP 5.4+ WP 4.0+ Updated Dec 5, 2024
accordionelementorfaqtab
91
A · Safe
CVEs total2
Unpatched0
Last CVEDec 5, 2024
Safety Verdict

Is XLTab – Accordions and Tabs for Elementor Page Builder Safe to Use in 2026?

Generally Safe

Score 91/100

XLTab – Accordions and Tabs for Elementor Page Builder has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Dec 5, 2024Updated 1yr ago
Risk Assessment

The "xl-tab" plugin v1.5 exhibits a mixed security posture. On the positive side, static analysis reveals no dangerous functions, no raw SQL queries, and no file operations or external HTTP requests, suggesting some good coding practices. However, a significant concern is the extremely low percentage (13%) of properly escaped output, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities being present. The absence of nonce and capability checks on the single identified entry point (a shortcode) is also a considerable risk, as it implies that this entry point is likely unprotected and could be exploited by unauthenticated users.

The plugin's vulnerability history shows two past medium-severity vulnerabilities, specifically Authorization Bypass Through User-Controlled Key and Improper Neutralization of Input During Web Page Generation (XSS). The recurrence of XSS in the past, coupled with the current static analysis showing poor output escaping, strongly suggests that XSS remains a persistent and significant threat for this plugin. While there are currently no unpatched CVEs, the historical pattern of vulnerabilities, particularly XSS, combined with the identified lack of output escaping and authorization checks on the entry point, warrants caution.

In conclusion, while the plugin avoids certain common pitfalls like raw SQL or dangerous functions, the high risk of XSS due to poor output escaping and the unprotected shortcode entry point are major weaknesses. The historical prevalence of XSS further amplifies these concerns. Users should exercise caution and consider the risks associated with these identified issues.

Key Concerns

  • Low output escaping percentage (13%)
  • Missing capability checks on entry point
  • Missing nonce checks on entry point
  • Two past medium vulnerabilities (XSS)
Vulnerabilities
2

XLTab – Accordions and Tabs for Elementor Page Builder Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-10689medium · 4.3Authorization Bypass Through User-Controlled Key

XLTab – Accordions and Tabs for Elementor Page Builder <= 1.4 - Authenticated (Contributor+) Post Disclosure

Dec 5, 2024 Patched in 1.5 (1d)
CVE-2024-47375medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

XLTab – Accordions and Tabs for Elementor Page Builder <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 30, 2024 Patched in 1.4 (11d)
Code Analysis
Analyzed Mar 16, 2026

XLTab – Accordions and Tabs for Elementor Page Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

13% escaped16 total outputs
Attack Surface

XLTab – Accordions and Tabs for Elementor Page Builder Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[XLTAB_INSERT_TPL] inc\template-lib.php:26
WordPress Hooks 8
actionadmin_initinc\optin.php:9
actionadmin_initinc\optin.php:10
actionadmin_noticesinc\optin.php:34
actionadmin_noticesinc\optin.php:36
actionelementor/frontend/after_register_scriptsindex.php:75
actionelementor/widgets/widgets_registeredindex.php:76
actiontemplate_redirectindex.php:77
actionelementor/initindex.php:78
Maintenance & Trust

XLTab – Accordions and Tabs for Elementor Page Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedDec 5, 2024
PHP min version5.4
Downloads19K

Community Trust

Rating80/100
Number of ratings4
Active installs1K
Developer Profile

XLTab – Accordions and Tabs for Elementor Page Builder Developer Profile

webangon

5 plugins · 43K total installs

74
trust score
Avg Security Score
80/100
Avg Patch Time
55 days
View full developer profile
Detection Fingerprints

How We Detect XLTab – Accordions and Tabs for Elementor Page Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xl-tab/assets/js/xltab-lib.js/wp-content/plugins/xl-tab/assets/js/xltab.js
Script Paths
/wp-content/plugins/xl-tab/assets/js/xltab-lib.js/wp-content/plugins/xl-tab/assets/js/xltab.jswidgets/accordion/style.css

HTML / DOM Fingerprints

CSS Classes
xltab-wrapper
Data Attributes
data-tab-switchdata-toggle
JS Globals
xltab_obj
FAQ

Frequently Asked Questions about XLTab – Accordions and Tabs for Elementor Page Builder