PatchSiren

Essential Addons for Elementor CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Essential Addons for Elementor CVE published 2026-08-14

CVE-2026-18039

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator. This vulnerability affects WordPress site administrators using the Essential Addons for Elementor plugin and security teams monitoring for [truncated]