Description
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify the title and metadata of arbitrary WordPress posts or permanently delete arbitrary WordPress posts by supplying an attacker-controlled popup_id. The required nonce is emitted on the edit-jltma_popup admin screen, which is accessible to Contributors because the jltma_popup custom post type is registered with capability_type='post'.
Published: 2026-09-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Content Modification/Deletion
Action: Immediate Patch
AI Analysis

Impact

The Master Addons for Elementor plugin suffers from an authorization bypass that permits any authenticated user with contributor-level or higher privileges to modify the title and metadata of any WordPress post or permanently delete a post by supplying an attacker‑controlled popup_id. The vulnerability stems from the plugin failing to verify that the user is authorized to perform the requested action. This flaw allows a threat actor to tamper with or erase content without needing root or administrative access, thereby compromising data integrity and availability.

Affected Systems

WordPress sites using the Master Addons for Elementor plugin, version 3.2.2 or earlier. The plugin registers a custom post type (jltma_popup) with capability_type='post', which inadvertently grants contributors the capability to edit posts of that type. All installations of the affected plugin fall within this scope unless an earlier or later unsupported version is in use.

Risk and Exploitability

The CVSS score of 8.1 classifies this issue as high severity. The EPSS score of less than 1% indicates that exploitation is currently improbable, but the vulnerable code can be reached by anyone who has contributed-post permissions, a role that is common on many sites. The vulnerability is not listed in the CISA KEV catalog. Attackers would target the nonce‑protected popup editing interface, which is accessible to contributors, and supply a crafted popup_id to change or delete existing posts. The flaw is exploitable without additional privileges beyond those normally granted to a contributor.

Generated by OpenCVE AI on September 19, 2026 at 20:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Master Addons for Elementor to version 3.2.3 or later.
  • If an upgrade is not possible, remove or disable the jltma_popup custom post type from the plugin’s code to prevent contributors from accessing it.
  • Revoke contributor or higher level permissions from users who only need read‑only access until the plugin is patched.
  • Monitor post modification logs for unexpected changes until the fix is applied.

Generated by OpenCVE AI on September 19, 2026 at 20:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Pixarlabs
Pixarlabs master Addons For Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits
Wordpress
Wordpress wordpress
Vendors & Products Pixarlabs
Pixarlabs master Addons For Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify the title and metadata of arbitrary WordPress posts or permanently delete arbitrary WordPress posts by supplying an attacker-controlled popup_id. The required nonce is emitted on the edit-jltma_popup admin screen, which is accessible to Contributors because the jltma_popup custom post type is registered with capability_type='post'.
Title Master Addons for Elementor <= 3.2.2 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via 'popup_id' Parameter
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Pixarlabs Master Addons For Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:21:51.115Z

Reserved: 2026-09-03T18:49:29.851Z

Link: CVE-2026-85410

cve-icon Vulnrichment

Updated: 2026-09-19T14:12:52.485Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T09:16:42.500

Modified: 2026-09-19T15:17:06.110

Link: CVE-2026-85410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:15:18Z

Weaknesses