Impact
The Master Addons for Elementor WordPress plugin, in versions below 3.1.9, fails to enforce authorization on the AJAX action responsible for deactivating its Popup Builder popups. The vulnerability relies solely on a nonce that is publicly exposed to every visitor, allowing attackers without valid credentials to permanently disable any popup on the site. This lack of proper access control is a classic example of the CWE-862 weakness, where insufficient authorization checks enable unauthorized modification of critical component behavior.
Affected Systems
Any installation of the Master Addons for Elementor plugin prior to version 3.1.9 is affected. The issue is specific to the plugin’s popup functionality and impacts WordPress sites that rely on Master Addons to display popups, such as those used for marketing, lead capture, or user notifications.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability presents a moderate severity. The EPSS score is below 1 %, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via unauthenticated HTTP requests to the jltma_popup_disable_expired AJAX endpoint, which any site visitor can form because the nonce is openly rendered. An attacker can craft a request to permanently disable the desired popup, potentially disrupting site functionality or undermining the business objectives that rely on those popups.
OpenCVE Enrichment