Authorization Bypass in Master Addons for Elementor Plugin
CVE-2026-85410

8.1HIGH

What is CVE-2026-85410?

The Master Addons for Elementor plugin for WordPress suffers from an authorization bypass issue that allows authenticated attackers with contributor-level access or higher to manipulate post titles and metadata. Attackers can potentially delete any post by exploiting a weakness in nonce verification on the edit-jltma_popup admin screen, which is associated with the pop-up feature of the plugin. This vulnerability arises from the jltma_popup custom post type being registered in a manner accessible to unauthorized users.

Affected Version(s)

Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits 0 <= 3.2.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.