Arbitrary File Upload Vulnerability in Master Addons for Elementor by WordPress
CVE-2026-75921

7.2HIGH

What is CVE-2026-75921?

The Master Addons for Elementor plugin for WordPress has a significant security vulnerability that allows authenticated users with elevated permissions to upload malicious files. Specifically, due to a misconfiguration of authorization requirements in the upload_template_kit function, users with editor-level access can bypass necessary safeguards. This vulnerability arises from the lack of strict file type filtering for uploads and allows for the potential execution of arbitrary code on the server, posing a serious threat to website integrity and security.

Affected Version(s)

Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits 0 <= 3.1.9

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.