Junglewise Threat Intelligence

CVE-2026-91015: Master Addons for Elementor missing authorization in AJAX popup deactivation

CVE-2026-91015 · Severity: medium · CVSS 5.3 · Published 2026-09-17

Technologies: JoomlaTheme Master Addons for Elementor.

Executive brief

The Master Addons for Elementor WordPress plugin contains a flaw in its Popup Builder feature that allows unauthenticated visitors to permanently disable popups on websites. The vulnerability bypasses authorization checks by relying only on a publicly visible security token, enabling attackers to disrupt critical popup functionality used for marketing, notifications, and customer engagement.

Technical details

The plugin fails to enforce authorization checks on the AJAX action jltma_popup_disable_expired, which deactivates Popup Builder popups. The vulnerability relies solely on a nonce that is publicly output to all visitors, making the nonce predictable and useless as a security control. An unauthenticated attacker can craft an AJAX request to permanently disable any popup on the site. This is a broken access control vulnerability (CWE-862) that was patched in version 3.1.9.

Affected products

  • JoomlaTheme Master Addons for Elementor before 3.1.9

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in version 3.1.9

References