← WordPress Vulnerabilities
WordPress security by component

Master Addons for Elementor

Master Addons for Elementor adds Elementor widgets, templates, extensions, and design elements for creating customized WordPress pages and layouts.

Master Addons for Elementor (master-addons) is a WordPress plugin with 27 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 8.8.

Plugin slug: master-addons

CVE-2026-62089: Master Addons for Elementor permits low-privilege abuse

Master Addons for Elementor through 3.2.2 has a missing-authorization flaw that permits privilege abuse by a low-privilege authenticated user. The CNA vector requires no user interaction and rates availability impact as high and integrity impact as low. The authoritative export does not identify the minimum WordPress role, endpoint, action, parameter, protected operation, or resulting privilege.

PublishedSep 11, 2026
Known safe version3.2.3
Published vulnerabilities for master-addons
Safe version
Sep 11, 2026 CVE-2026-62089
Master Addons for Elementor permits low-privilege abuse
Master Addons for Elementor through 3.2.2 has a missing-authorization flaw that permits privilege abuse by a low-privilege authenticated user. The CNA vector requires no user interaction and rates availability impact as high and integrity impact as low. The authoritative export does not identify the minimum WordPress role, endpoint, action, parameter, protected operation, or resulting privilege.
3.2.3
CVE7.1
NVDPending
Sep 01, 2026 CVE-2026-75921
Master Addons permits Editor-level arbitrary file upload
Master Addons through 3.1.9 protects its upload_template_kit() AJAX handler with upload_files rather than manage_options. Editors can obtain the localized nonce from the Pages list, submit a template-kit ZIP, and exploit the lack of per-entry file-type filtering after extraction to place potentially executable files on the server.
See mitigation notes
CVE7.2
NVDPending
Jun 06, 2026 CVE-2026-9281
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits: Cross-site scripting
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.1.0.
See mitigation notes
CVE6.4
NVDPending
Mar 13, 2026 CVE-2026-32462
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Mar 02, 2026 CVE-2026-3132
Master Addons for Elementor Premium: Code execution
Master Addons for Elementor Premium is affected by code execution. Exploitation requires an authenticated subscriber account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Feb 20, 2026 CVE-2024-52387
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Dec 31, 2025 CVE-2025-63053
Master Addons for Elementor: A security weakness
Master Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 24, 2025 CVE-2023-40679
Master Addons for Elementor: A security weakness
Master Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Dec 09, 2025 CVE-2025-63055
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Aug 12, 2025 CVE-2025-8874
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations: Cross-site scripting
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Jul 16, 2025 CVE-2025-5284
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations: Cross-site scripting
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Mar 04, 2025 CVE-2025-0433
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations: Cross-site scripting
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 04, 2025 CVE-2024-9618
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations: Cross-site scripting
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 07, 2025 CVE-2024-9502
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations: Cross-site scripting
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Sep 10, 2024 CVE-2024-6282
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor: Cross-site scripting
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Jul 20, 2024 CVE-2024-38710
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Jun 09, 2024 CVE-2024-35660
Master Addons for Elementor: A security weakness
Master Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD9.8
Jun 08, 2024 CVE-2024-35702
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 08, 2024 CVE-2024-35688
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 07, 2024 CVE-2024-5542
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor: Cross-site scripting
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Jun 07, 2024 CVE-2024-5382
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor: A security weakness
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD5.3
May 16, 2024 CVE-2024-3134
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor: Cross-site scripting
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 16, 2024 CVE-2024-4580
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor: Cross-site scripting
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 02, 2024 CVE-2024-4265
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor: Cross-site scripting
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 29, 2024 CVE-2024-33595
Master Addons for Elementor: A security weakness
Master Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Mar 27, 2024 CVE-2024-29911
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 27, 2024 CVE-2024-2139
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4