Xpro Addons For Beaver Builder – Lite Security & Risk Analysis

wordpress.org/plugins/xpro-addons-beaver-builder-elementor

Xpro Addons for Beaver Builder – Lite is a simple drag-and-drop creative module pack that lets you create stunning websites.

700 active installs v1.5.7 PHP + WP 4.6+ Updated Feb 20, 2026
beaver-addonsbeaver-builderbeaver-builder-add-onsbeaver-builder-addonbeaver-builder-free
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 19, 2025
Safety Verdict

Is Xpro Addons For Beaver Builder – Lite Safe to Use in 2026?

Generally Safe

Score 99/100

Xpro Addons For Beaver Builder – Lite has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 19, 2025Updated 1mo ago
Risk Assessment

The plugin "xpro-addons-beaver-builder-elementor" v1.5.7 exhibits a generally good security posture based on the static analysis. The absence of any critical or high severity taint flows, along with 100% of SQL queries utilizing prepared statements, are strong indicators of secure coding practices. The significant number of output escaping (88%) further contributes to a positive assessment, suggesting a conscious effort to prevent Cross-Site Scripting vulnerabilities. The plugin also correctly implements nonce checks for its AJAX handlers and has capability checks in place, which are crucial for securing these entry points.

However, there are a couple of areas that warrant attention. While the attack surface is not inherently large, having 6 AJAX handlers where none are explicitly noted as unprotected is a good start, but the fact that capability checks are present on only one indicates potential for privilege escalation if the other handlers are not adequately protected by their context or other implicit checks. Furthermore, the plugin has a history of a medium severity Cross-Site Scripting vulnerability, with the last recorded vulnerability dated May 19, 2025. While this vulnerability is currently unpatched and the date seems to be in the future, it serves as a reminder of past issues and the need for continued vigilance and prompt patching of any future discoveries.

In conclusion, the plugin demonstrates strong foundational security practices, particularly in data sanitization and preventing direct database manipulation. The primary areas for improvement lie in ensuring robust access controls on all AJAX handlers and maintaining a proactive approach to addressing any newly discovered vulnerabilities, given the past occurrence of XSS.

Key Concerns

  • Medium severity CVE history
  • Limited capability checks on AJAX handlers
Vulnerabilities
1

Xpro Addons For Beaver Builder – Lite Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-48232medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Xpro Addons For Beaver Builder &#8211; Lite <= 1.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 19, 2025 Patched in 1.5.6 (11d)
Code Analysis
Analyzed Mar 16, 2026

Xpro Addons For Beaver Builder – Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
12 prepared
Unescaped Output
127
934 escaped
Nonce Checks
8
Capability Checks
1
File Operations
4
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared12 total queries

Output Escaping

88% escaped1061 total outputs
Attack Surface

Xpro Addons For Beaver Builder – Lite Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_xpro_cloud_dat_fileclasses\class-xpro-templates-liberary.php:70
authwp_ajax_xpro_cloud_dat_file_removeclasses\class-xpro-templates-liberary.php:71
authwp_ajax_xpro_cloud_dat_file_fetchclasses\class-xpro-templates-liberary.php:72
authwp_ajax_xpro_beaver_addons_admin_actiondashboard\classes\ajax.php:11
authwp_ajax_tnit_builder_emailmodules\tnit-contact-form\tnit-contact-form.php:27
noprivwp_ajax_tnit_builder_emailmodules\tnit-contact-form\tnit-contact-form.php:28
WordPress Hooks 17
actionadmin_menuclasses\class-custom-post-type.php:14
filterfl_builder_post_typesclasses\class-custom-post-type.php:16
filterfl_builder_admin_settings_post_typesclasses\class-custom-post-type.php:17
filtersingle_templateclasses\class-custom-post-type.php:19
actionadmin_menuclasses\class-xpro-addons-for-bb-init.php:17
actioninitclasses\class-xpro-addons-for-bb-init.php:18
actionfl_builder_after_save_layoutclasses\class-xpro-addons-for-bb-init.php:19
filterupload_mimesclasses\class-xpro-addons-for-bb-init.php:21
actionadmin_enqueue_scriptsclasses\class-xpro-addons-for-bb-init.php:24
actionadmin_enqueue_scriptsclasses\class-xpro-addons-for-bb-init.php:26
actionxpro_cloud_template_buttonsclasses\class-xpro-templates-liberary.php:75
actionadmin_initclasses\class-xpro-templates-liberary.php:78
filterfl_builder_template_selector_dataclasses\class-xpro-ui-panels.php:46
actioninitxpro-addons-beaver-builder-elementor.php:37
actionplugins_loadedxpro-addons-beaver-builder-elementor.php:40
actionadmin_noticesxpro-addons-beaver-builder-elementor.php:75
actionadmin_noticesxpro-addons-beaver-builder-elementor.php:81
Maintenance & Trust

Xpro Addons For Beaver Builder – Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs700
Developer Profile

Xpro Addons For Beaver Builder – Lite Developer Profile

Xpro

7 plugins · 42K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
19 days
View full developer profile
Detection Fingerprints

How We Detect Xpro Addons For Beaver Builder – Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xpro-addons-beaver-builder-elementor/assets/css/xpro-addons-beaver-builder-elementor-admin.css/wp-content/plugins/xpro-addons-beaver-builder-elementor/assets/js/xpro-addons-beaver-builder-elementor-admin.js/wp-content/plugins/xpro-addons-beaver-builder-elementor/assets/css/xpro-addons-icon.css/wp-content/plugins/xpro-addons-beaver-builder-elementor/assets/css/frontend.css
Script Paths
/wp-content/plugins/xpro-addons-beaver-builder-elementor/assets/js/xpro-addons-beaver-builder-elementor-admin.js
Version Parameters
xpro-addons-beaver-builder-elementor/assets/css/xpro-addons-beaver-builder-elementor-admin.css?ver=xpro-addons-beaver-builder-elementor/assets/js/xpro-addons-beaver-builder-elementor-admin.js?ver=xpro-addons-beaver-builder-elementor/assets/css/xpro-addons-icon.css?ver=xpro-addons-beaver-builder-elementor/assets/css/frontend.css?ver=

HTML / DOM Fingerprints

CSS Classes
xpro-addons-for-bb
Data Attributes
data-xpro-addons-for-bb
JS Globals
XproAddonsForBBAdmin
FAQ

Frequently Asked Questions about Xpro Addons For Beaver Builder – Lite