{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/master-addons-for-elementor--3.2.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:master_addons:master_addons_for_elementor:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-85410"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Master Addons for Elementor (\u003c= 3.2.2)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","authorization-bypass"],"_cs_type":"advisory","_cs_vendors":["Master Addons"],"content_html":"\u003cp\u003eThe Master Addons for Elementor plugin for WordPress is vulnerable to an authorization bypass flaw, tracked as CVE-2026-85410, affecting all versions up to and including 3.2.2. The vulnerability stems from improper capability verification when handling the jltma_popup custom post type. Because this post type is registered with 'capability_type' set to 'post', WordPress grants contributor-level users access to the associated admin screen. This screen exposes a nonce required to execute administrative actions. Attackers with contributor access can leverage this exposed nonce to bypass authorization controls, allowing them to modify the title and metadata of arbitrary posts or permanently delete posts by supplying an attacker-controlled 'popup_id' parameter to the plugin's backend endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users with contributor-level permissions to escalate their capabilities to delete or modify any post on the affected WordPress site, potentially leading to unauthorized data modification, defacement, or total loss of content. This impact is significant for sites with multiple contributors or where contributor accounts may be compromised.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately by upgrading the Master Addons for Elementor plugin to a version beyond 3.2.2.\u003c/li\u003e\n\u003cli\u003eAudit user accounts with contributor-level access to identify potentially unauthorized activity or compromise.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests targeting the plugin's administrative endpoints associated with 'jltma_popup' actions from contributor accounts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T10:06:20Z","date_published":"2026-09-18T10:06:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-master-addons-bypass/","summary":"An authorization bypass vulnerability in the Master Addons for Elementor WordPress plugin allows authenticated contributors to modify or delete arbitrary posts.","title":"Authorization Bypass in Master Addons for Elementor","url":"https://feed.craftedsignal.io/briefs/2026-09-master-addons-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Master Addons for Elementor (\u003c= 3.2.2)","version":"https://jsonfeed.org/version/1.1"}