Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Master Addons for Elementor — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Master Addons for Elementor, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities specific to the Master Addons for Elementor product, developed by the Elementor ecosystem vendor. It collects data on known software weaknesses, covering advisories published over the past several years. Readers can use this resource to track the vendor's recent security announcements, understand the specific class of flaws commonly found in this addon suite, and review the complete vulnerability history for the product. The collection focuses on defects such as cross-site scripting, insecure direct object references, and missing authentication checks that have been reported in various releases. By consolidating these records, the page provides a centralized view of the product's security posture, allowing users to identify patterns in past incidents and assess current risk exposure. No specific CVE identifiers are listed here; instead, the emphasis is on the nature and frequency of reported weaknesses within the Master Addons for Elementor environment.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-91015 Master Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via jltma_popup_disable_expired - - 2026-09-17
CVE-2026-62089 WordPress Master Addons for Elementor plugin <= 3.2.2 - Broken Access Control vulnerability CWE-862 7.1 High 2026-09-11
CVE-2026-32462 WordPress Master Addons for Elementor plugin <= 2.1.3 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2026-03-13
CVE-2024-52387 WordPress Master Addons plugin <= 2.0.9.9.4 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2026-02-20
CVE-2025-63053 WordPress Master Addons for Elementor plugin <= 2.0.9.9.4 - Insecure Direct Object References (IDOR) vulnerability CWE-639 5.3 Medium 2025-12-31
CVE-2023-40679 WordPress Master Elementor Addons plugin <= 2.0.5.3 - Broken Access Control vulnerability CWE-862 6.5 Medium 2025-12-24
CVE-2025-63055 WordPress Master Addons for Elementor plugin <= 2.0.9.9.4 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-12-09
CVE-2024-38710 WordPress Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin <= 2.0.6.2 - Cross Site Scripting (XSS) vulnerability CWE-79 5.9 Medium 2024-07-20
CVE-2024-35660 WordPress Master Addons for Elementor plugin <= 2.0.5.4.1 - Broken Access Control on API vulnerability CWE-862 6.5 Medium 2024-06-09
CVE-2024-35688 WordPress Master Addons for Elementor plugin <= 2.0.5.9 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-06-08
CVE-2024-35702 WordPress Master Addons for Elementor plugin <= 2.0.6.0 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-06-08
CVE-2024-33595 WordPress Master Addons for Elementor plugin <= 2.0.5.4.1 - Broken Access Control on Duplicate Post vulnerability CWE-862 4.3 Medium 2024-04-29
CVE-2024-29911 WordPress Master Addons for Elementor plugin <= 2.0.5.4.1 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-03-27
CVE-2022-0327 Master Addons for Elementor < 1.8.2 - Reflected Cross-Site Scripting CWE-79 6.1 - 2022-03-14

All 14 known CVE vulnerabilities affecting Master Addons for Elementor with full Chinese analysis, references, and POCs where available.