Description
The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowing unauthenticated attackers to permanently disable any popup on the site.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service to Popup Features
Action: Update Plugin
AI Analysis

Impact

The Master Addons for Elementor WordPress plugin, in versions below 3.1.9, fails to enforce authorization on the AJAX action responsible for deactivating its Popup Builder popups. The vulnerability relies solely on a nonce that is publicly exposed to every visitor, allowing attackers without valid credentials to permanently disable any popup on the site. This lack of proper access control is a classic example of the CWE-862 weakness, where insufficient authorization checks enable unauthorized modification of critical component behavior.

Affected Systems

Any installation of the Master Addons for Elementor plugin prior to version 3.1.9 is affected. The issue is specific to the plugin’s popup functionality and impacts WordPress sites that rely on Master Addons to display popups, such as those used for marketing, lead capture, or user notifications.

Risk and Exploitability

With a CVSS score of 5.3 the vulnerability presents a moderate severity. The EPSS score is below 1 %, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via unauthenticated HTTP requests to the jltma_popup_disable_expired AJAX endpoint, which any site visitor can form because the nonce is openly rendered. An attacker can craft a request to permanently disable the desired popup, potentially disrupting site functionality or undermining the business objectives that rely on those popups.

Generated by OpenCVE AI on September 18, 2026 at 04:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an update to Master Addons for Elementor version 3.1.9 or later, which removes the vulnerability.
  • If an immediate update is not possible, restrict the jltma_popup_disable_expired AJAX action to authenticated users only by implementing server‑side checks or by disabling the endpoint in a web‑application firewall.
  • Block the AJAX endpoint or disable the Master Addons plugin altogether until a patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 04:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowing unauthenticated attackers to permanently disable any popup on the site.
Title Master Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via jltma_popup_disable_expired
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:25:38.140Z

Reserved: 2026-09-14T16:39:59.955Z

Link: CVE-2026-91015

cve-icon Vulnrichment

Updated: 2026-09-17T12:09:11.268Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:53.090

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-91015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:04Z

Weaknesses