Master Addons for Elementor
Master Addons for Elementor adds Elementor widgets, templates, extensions, and design elements for creating customized WordPress pages and layouts.
Master Addons for Elementor (master-addons) is a WordPress plugin with 27 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 8.8.
master-addonsCVE-2026-62089: Master Addons for Elementor permits low-privilege abuse
Master Addons for Elementor through 3.2.2 has a missing-authorization flaw that permits privilege abuse by a low-privilege authenticated user. The CNA vector requires no user interaction and rates availability impact as high and integrity impact as low. The authoritative export does not identify the minimum WordPress role, endpoint, action, parameter, protected operation, or resulting privilege.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-62089
Master Addons for Elementor permits low-privilege abuse
Master Addons for Elementor through 3.2.2 has a missing-authorization flaw that permits privilege abuse by a low-privilege authenticated user. The CNA vector requires no user interaction and rates availability impact as high and integrity impact as low. The authoritative export does not identify the minimum WordPress role, endpoint, action, parameter, protected operation, or resulting privilege.
|
3.2.3 |
CVE7.1
NVDPending
|
| Sep 01, 2026 |
CVE-2026-75921
Master Addons permits Editor-level arbitrary file upload
Master Addons through 3.1.9 protects its upload_template_kit() AJAX handler with upload_files rather than manage_options. Editors can obtain the localized nonce from the Pages list, submit a template-kit ZIP, and exploit the lack of per-entry file-type filtering after extraction to place potentially executable files on the server.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Jun 06, 2026 |
CVE-2026-9281
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits: Cross-site scripting
Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.1.0.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Mar 13, 2026 |
CVE-2026-32462
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Mar 02, 2026 |
CVE-2026-3132
Master Addons for Elementor Premium: Code execution
Master Addons for Elementor Premium is affected by code execution. Exploitation requires an authenticated subscriber account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Feb 20, 2026 |
CVE-2024-52387
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Dec 31, 2025 |
CVE-2025-63053
Master Addons for Elementor: A security weakness
Master Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 24, 2025 |
CVE-2023-40679
Master Addons for Elementor: A security weakness
Master Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 09, 2025 |
CVE-2025-63055
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 12, 2025 |
CVE-2025-8874
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations: Cross-site scripting
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jul 16, 2025 |
CVE-2025-5284
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations: Cross-site scripting
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Mar 04, 2025 |
CVE-2025-0433
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations: Cross-site scripting
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 04, 2025 |
CVE-2024-9618
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations: Cross-site scripting
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jan 07, 2025 |
CVE-2024-9502
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations: Cross-site scripting
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Sep 10, 2024 |
CVE-2024-6282
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor: Cross-site scripting
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jul 20, 2024 |
CVE-2024-38710
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Jun 09, 2024 |
CVE-2024-35660
Master Addons for Elementor: A security weakness
Master Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD9.8
|
| Jun 08, 2024 |
CVE-2024-35702
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jun 08, 2024 |
CVE-2024-35688
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jun 07, 2024 |
CVE-2024-5542
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor: Cross-site scripting
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Jun 07, 2024 |
CVE-2024-5382
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor: A security weakness
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD5.3
|
| May 16, 2024 |
CVE-2024-3134
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor: Cross-site scripting
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 16, 2024 |
CVE-2024-4580
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor: Cross-site scripting
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 02, 2024 |
CVE-2024-4265
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor: Cross-site scripting
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 29, 2024 |
CVE-2024-33595
Master Addons for Elementor: A security weakness
Master Addons for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Mar 27, 2024 |
CVE-2024-29911
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 27, 2024 |
CVE-2024-2139
Master Addons for Elementor: Cross-site scripting
Master Addons for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|