<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Master Addons for Elementor (&lt;= 3.2.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/master-addons-for-elementor--3.2.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 10:06:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/master-addons-for-elementor--3.2.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Master Addons for Elementor</title><link>https://feed.craftedsignal.io/briefs/2026-09-master-addons-bypass/</link><pubDate>Fri, 18 Sep 2026 10:06:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-master-addons-bypass/</guid><description>An authorization bypass vulnerability in the Master Addons for Elementor WordPress plugin allows authenticated contributors to modify or delete arbitrary posts.</description><content:encoded><![CDATA[<p>The Master Addons for Elementor plugin for WordPress is vulnerable to an authorization bypass flaw, tracked as CVE-2026-85410, affecting all versions up to and including 3.2.2. The vulnerability stems from improper capability verification when handling the jltma_popup custom post type. Because this post type is registered with 'capability_type' set to 'post', WordPress grants contributor-level users access to the associated admin screen. This screen exposes a nonce required to execute administrative actions. Attackers with contributor access can leverage this exposed nonce to bypass authorization controls, allowing them to modify the title and metadata of arbitrary posts or permanently delete posts by supplying an attacker-controlled 'popup_id' parameter to the plugin's backend endpoints.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated users with contributor-level permissions to escalate their capabilities to delete or modify any post on the affected WordPress site, potentially leading to unauthorized data modification, defacement, or total loss of content. This impact is significant for sites with multiple contributors or where contributor accounts may be compromised.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch immediately by upgrading the Master Addons for Elementor plugin to a version beyond 3.2.2.</li>
<li>Audit user accounts with contributor-level access to identify potentially unauthorized activity or compromise.</li>
<li>Review web server access logs for anomalous POST requests targeting the plugin's administrative endpoints associated with 'jltma_popup' actions from contributor accounts.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>authorization-bypass</category></item></channel></rss>