Impact
The Master Addons for Elementor plugin suffers from an authorization bypass that permits any authenticated user with contributor-level or higher privileges to modify the title and metadata of any WordPress post or permanently delete a post by supplying an attacker‑controlled popup_id. The vulnerability stems from the plugin failing to verify that the user is authorized to perform the requested action. This flaw allows a threat actor to tamper with or erase content without needing root or administrative access, thereby compromising data integrity and availability.
Affected Systems
WordPress sites using the Master Addons for Elementor plugin, version 3.2.2 or earlier. The plugin registers a custom post type (jltma_popup) with capability_type='post', which inadvertently grants contributors the capability to edit posts of that type. All installations of the affected plugin fall within this scope unless an earlier or later unsupported version is in use.
Risk and Exploitability
The CVSS score of 8.1 classifies this issue as high severity. The EPSS score of less than 1% indicates that exploitation is currently improbable, but the vulnerable code can be reached by anyone who has contributed-post permissions, a role that is common on many sites. The vulnerability is not listed in the CISA KEV catalog. Attackers would target the nonce‑protected popup editing interface, which is accessible to contributors, and supply a crafted popup_id to change or delete existing posts. The flaw is exploitable without additional privileges beyond those normally granted to a contributor.
OpenCVE Enrichment