Unrated severityNVD Advisory· Published Sep 17, 2026
CVE-2026-91015
CVE-2026-91015
Description
The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowing unauthenticated attackers to permanently disable any popup on the site.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.1.9
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.