CVE-2026-3132Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via the 'JLTMA_Widget_Admin::render_preview'. This is due to missing capability check. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute code on the server.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-03-02); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-03-02: 4Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-30: 1Technical Details · 2026-03-02: 4Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 103-0203-0503-0603-30
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-024
Disclosure4
2026-03-051
Disclosure1
2026-03-061
Disclosure1
2026-03-301
General1
Full discourse7 posts
  • David@DavidMarquet19
    General

    📌 Top CVEs recientes (CVSS>=7.0): 1. ⚠️ CVE-2025-48605 (CVSS: 8.4) 2. ⚠️ CVE-2025-48602 (CVSS: 8.4) 3. ⚠️ CVE-2025-48582 (CVSS: 8.4) 4. 💉 CVE-2026-3180 (CVSS: 7.5) 5. 🔥 CVE-2026-3132 (CVSS: 8.8) #CyberSecurity #CVE #Infosec

    Post summary

    A brief list of five recent high‑CVSS CVEs, lacking detailed technical or operational information.

    00000183
    162 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3132 (CVSS:8.8, HIGH) is Awaiting Analysis. The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up t..https://nvd.nist.gov/vuln/detail/CVE-2026-3132 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-3132 is a high‑severity Remote Code Execution vulnerability affecting the Master Addons plugin for Elementor Premium; details are listed on NVD but no exploit or patch information is provided.

    0000037
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3132 (CVSS:8.8, HIGH) is Awaiting Analysis. The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up t..https://nvd.nist.gov/vuln/detail/CVE-2026-3132 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3132, a remote code execution flaw in Master Addons for Elementor Premium (CVSS 8.8), but provides no PoC, exploit, or patch details.

    0000030
    173 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3132 - High The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via the 'JLTMA_Widget_Admin::render_preview'. Th... https://www.thehackerwire.com/vulnerability/CVE-2026-3132/ https://t.co/UxgU8evQ4x

    Post summary

    The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution via the JLTMA_Widget_Admin::render_preview function in all versions up to 2.1.3.

    0000047
    122 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3132: HIGH] WordPress Master Addons for Elementor Premium plugin has a critical vulnerability allowing remote code execution up to version 2.1.3. Attackers can execute code with Subscriber-level acce...#cve,CVE-2026-3132,#cybersecurity https://cvefind.com/CVE-2026-3132

    Post summary

    A critical RCE vulnerability (CVE-2026-3132) in WordPress Master Addons for Elementor Premium plugin affects versions up to 2.1.3, allowing attackers with Subscriber-level access to execute code.

    0000062
    590 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3132 The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via the 'JLTMA_Widget_Ad… https://www.cve.org/CVERecord?id=CVE-2026-3132 ----- Traducción: CVE-2026-3132 El … http://infoflow.cloud`

    Post summary

    The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution via the JLTMA_Widget_Ad component, affecting all versions up to 2.1.3.

    0000038
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3132 The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.3 via the 'JLTMA_Widget_Ad… https://www.cve.org/CVERecord?id=CVE-2026-3132

    Post summary

    The Master Addons for Elementor Premium plugin is vulnerable to RCE via the JLTMA_Widget_Ad component in all versions up to 2.1.3, as documented in CVE-2026-3132.

    00000234
    56.6K followersView on X

Explore more