PT-2026-84109 · WordPress · Master Addons For Elementor
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Master Addons for Elementor versions prior to 3.2.0
Description
An arbitrary file upload issue exists in the
upload template kit() AJAX handler. The flaw stems from incorrect authorization, as the handler only requires the upload files capability instead of the manage options capability used by similar handlers. Additionally, the plugin fails to filter file types for individual entries after a ZIP file is extracted. Authenticated attackers with editor-level access or higher can exploit this to upload executable files, potentially leading to remote code execution. Users with the edit pages capability can obtain the necessary nonces from the standard Pages list screen.Recommendations
Update to a version newer than 3.1.9.
As a temporary mitigation, restrict access to the
upload template kit() function for users with editor-level permissions.Fix
RCE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Master Addons For Elementor