Remote Code Execution Vulnerability in Master Addons for Elementor by WordPress
CVE-2026-3132

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 March 2026

What is CVE-2026-3132?

The Master Addons for Elementor Premium plugin for WordPress is susceptible to a Remote Code Execution vulnerability in versions up to and including 2.1.3. This flaw arises from missing capability checks in the 'JLTMA_Widget_Admin::render_preview' function, allowing authenticated attackers with Subscriber-level access or greater to execute arbitrary code on the server. This significant oversight can lead to severe security breaches, compromising the integrity of web applications leveraging this plugin.

Affected Version(s)

Master Addons for Elementor Premium * <= 2.1.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ren Voza
.