CVE-2026-62089
Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
- CWE
- CWE-862
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- Pixar Labs Master Addons for Elementor
Weakness type
Related vulnerabilities
- CVE-2026-81915 — In Concrete CMS below 9.5.3, Page Type update omits object-level authorization
- CVE-2026-62137 — WordPress bbPress plugin <= 2.6.14 - Sensitive Data Exposure vulnerability
- CVE-2026-62136 — WordPress Flexible Quantity – Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control vulnerability
- CVE-2026-62135 — WordPress Booktics plugin <= 1.0.24 - Broken Access Control vulnerability
- CVE-2026-62132 — WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability
- CVE-2026-62114 — WordPress Passster plugin <= 4.3.13 - Broken Access Control vulnerability
- CVE-2026-27378 — WordPress Deposits and Partial Payments for WooCommerce plugin <= 3.1.0 - Broken Access Control vulnerability
- CVE-2026-81909 — Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks