CVE-2026-91015
The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowing unauthenticated attackers to permanently disable any popup on the site.
- Published Sep 17, 2026
- CVSS 5.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available