Authorization Bypass in Master Addons for Elementor Plugin
CVE-2026-85410
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-85410?
The Master Addons for Elementor plugin for WordPress suffers from an authorization bypass issue that allows authenticated attackers with contributor-level access or higher to manipulate post titles and metadata. Attackers can potentially delete any post by exploiting a weakness in nonce verification on the edit-jltma_popup admin screen, which is associated with the pop-up feature of the plugin. This vulnerability arises from the jltma_popup custom post type being registered in a manner accessible to unauthorized users.
Affected Version(s)
Master Addons for Elementor β Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits 0 <= 3.2.2