Junglewise Threat Intelligence

CVE-2026-62089: Pixar Labs Master Addons for Elementor broken access control

CVE-2026-62089 · Severity: high · CVSS 7.1 · Published 2026-09-11

Technologies: Pixar Labs Master Addons for Elementor.

Executive brief

Master Addons for Elementor is a WordPress plugin that extends the Elementor page builder with additional content components and functionality. A broken access control vulnerability allows authenticated users with the Contributor role to access and potentially modify pages or perform actions they should not be permitted to perform, exposing sensitive site content and functionality to unauthorized modification.

Technical details

The vulnerability is a broken access control (CWE-639) issue in Master Addons for Elementor versions up to 3.2.2. An authenticated attacker with Contributor-level privileges can bypass authorization checks to access or manipulate restricted resources on the site. The vulnerability requires authentication and an account with at least Contributor role permissions. An attacker can exploit this to view, access, or potentially modify pages and actions beyond their granted role capabilities. The vulnerability was patched in version 3.2.3.

Affected products

  • Pixar Labs Master Addons for Elementor up to 3.2.2

Timeline

  • 2026-07-23: disclosed: Vulnerability reported to Patchstack
  • 2026-09-11: advisory: Published by Patchstack and NVD
  • 2026-09-11: patched: Version 3.2.3 released with fix

References