CVE-2026-91015 PUBLISHED

Master Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via jltma_popup_disable_expired

Assigner: WPScan
Reserved: 14.09.2026 Published: 17.09.2026 Updated: 17.09.2026

The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowing unauthenticated attackers to permanently disable any popup on the site.

Product Status

Vendor Unknown
Product Master Addons for Elementor
Versions Default: unaffected
  • affected from 3.0.0 to 3.1.9 (excl.)

Credits

  • JunHee CHO finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE