CPE
An improper authorization flaw in the Master Addons for Elementor WordPress plugin allows authenticated users with editor-level access to achieve remote code execution via arbitrary file uploads.