PT-2026-71968 · WordPress · Essential Addons For Elementor

·

CVE-2026-18039

·

Published

2026-08-14

·

Updated

2026-08-14

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Essential Addons for Elementor versions prior to 6.7.2
Description An issue exists where the plugin fails to prevent user-supplied registration fields from overwriting reserved account attributes. This allows unauthenticated attackers to register an account with an arbitrary role, such as administrator, on sites that have configured a custom profile field with a specific label. This is a mass assignment flaw, which occurs when an application takes user-provided data and binds it to an internal object without proper filtering.
Recommendations Update Essential Addons for Elementor to version 6.7.2 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18039

Affected Products

Essential Addons For Elementor