HIGH
Essential Addons for Elementor
CVE published 2026-08-14
CVE-2026-18039
The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator. This vulnerability affects WordPress site administrators using the Essential Addons for Elementor plugin and security teams monitoring for [truncated]