PT-2026-94180 · WordPress · Master Addons For Elementor
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Master Addons for Elementor versions prior to 3.1.9
Description
The plugin fails to perform an authorization check on the AJAX action used to deactivate Popup Builder popups. It relies solely on a nonce (a number used once to prevent replay attacks) that is publicly exposed to all visitors. This allows unauthenticated attackers to permanently disable any popup on the site via the
jltma popup disable expired action.Recommendations
Update to version 3.1.9 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Master Addons For Elementor