← العودة للجدول
CVE-2026-75921
CVE-2026-75921 — The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder
📅 2026-09-01
🟠 High 🔥 No NVD Vulnerability WordPress CVSS 7.2

📋 الوصف الكامل

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.9 via the upload_template_kit function. This is due to incorrect authorization on the upload_template_kit() AJAX handler, which requires only upload_files capability

💻 الأنظمة المتأثرة

WordPress

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-75921

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v3.1.9

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←