CVE-2026-62089
largeMissing Authorization in Master Addons for Elementor Allows Privilege Abuse
CVE-2026-62089 is a missing authorization flaw (CWE-862) in the Pixar Labs 'Master Addons for Elementor' WordPress plugin, meaning one or more of its routines fail to verify a user's capabilities before executing privileged actions. Because the flaw requires low privileges (CVSS PR:L), an attacker needs an account on the target site — even a low-level role such as subscriber — and can then send a crafted network request to trigger the unprotected function. Successful abuse lets a minimally privileged user perform privileged operations, with the published CVSS score (7.1 high) weighting the impact toward integrity changes and potentially high availability impact rather than data disclosure. Any WordPress site running Master Addons for Elementor version 3.2.2 or earlier is affected. There is no evidence of exploitation so far: the flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known.
What to do: Update Master Addons for Elementor to the latest patched release (any version newer than 3.2.2; check the WordPress.org plugin page or changelog for the current fixed version, as none is specified in the advisory). Until patched, review accounts with low-privilege roles and consider restricting unknown registered users, and verify logged-in-user activity for signs of unauthorized privileged actions. Admins of Elementor-based sites should confirm their installed plugin version in the WordPress dashboard.
| Pixar Labs Master Addons for Elementor (WordPress plugin) | through 3.2.2 (all versions from n/a through 3.2.2) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.