CVE-2026-85410: Master Addons for Elementor <= 3.2.2 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via 'popup_id' Parameter

Published Sep 18, 2026
·
Updated

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify the title and metadata of arbitrary WordPress posts or permanently delete arbitrary WordPress posts by supplying an attacker-controlled popupid. The required nonce is emitted on the edit-jltmapopup admin screen, which is accessible to Contributors because the jltmapopup custom post type is registered with capabilitytype='post'.

Affected Software

1 affected component
WordPress Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits<=3.2.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Master Addons for Elementor (Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits) to a version that resolves this vulnerability.

    Fixed in 3.2.2
  2. Compensating control

    Restrict access to the WordPress admin screen that exposes the required nonce on the edit-jltma_popup admin screen so that only users with appropriate authorization (beyond Contributor) can access it.

Event History

Sep 18, 2026
CVE Published
via MITRE·08:28 AM
Data Sourced
via MITRE·08:28 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be authenticated to WordPress with Contributor-level access or higher. They do not need victim interaction, and the attack can be performed remotely.

2

Does exploitation require access to the plugin's popup editing interface?

The required nonce is emitted on the edit-jltma_popup admin screen. Contributors can access that screen because the jltma_popup custom post type uses capability_type='post'.

3

What can a successful attacker change or delete?

A successful attacker can modify the title and metadata of arbitrary WordPress posts. They can also permanently delete arbitrary WordPress posts by controlling the popup_id parameter.

4

Which plugin versions are affected?

All versions up to and including 3.2.2 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203