ZeroHour

CVE-2026-62089

large

Missing Authorization in Master Addons for Elementor Allows Privilege Abuse

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-62089 is a missing authorization flaw (CWE-862) in the Pixar Labs 'Master Addons for Elementor' WordPress plugin, meaning one or more of its routines fail to verify a user's capabilities before executing privileged actions. Because the flaw requires low privileges (CVSS PR:L), an attacker needs an account on the target site — even a low-level role such as subscriber — and can then send a crafted network request to trigger the unprotected function. Successful abuse lets a minimally privileged user perform privileged operations, with the published CVSS score (7.1 high) weighting the impact toward integrity changes and potentially high availability impact rather than data disclosure. Any WordPress site running Master Addons for Elementor version 3.2.2 or earlier is affected. There is no evidence of exploitation so far: the flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known.

What to do: Update Master Addons for Elementor to the latest patched release (any version newer than 3.2.2; check the WordPress.org plugin page or changelog for the current fixed version, as none is specified in the advisory). Until patched, review accounts with low-privilege roles and consider restricting unknown registered users, and verify logged-in-user activity for signs of unauthorized privileged actions. Admins of Elementor-based sites should confirm their installed plugin version in the WordPress dashboard.

Affected
Pixar Labs Master Addons for Elementor (WordPress plugin)through 3.2.2 (all versions from n/a through 3.2.2)
Estimated exposure
large≈100,000 WordPress sites (plugin is listed with roughly 100,000+ active installations) — Master Addons for Elementor is a widely deployed Elementor add-on listed on WordPress.org with on the order of 100,000 active installs, so roughly that number of sites runs an affected version until they update.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

In the news

No ingested article mentions this CVE yet.