๐Ÿ” CVE Alert

CVE-2026-18039

UNKNOWN 0.0

Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.

Vendor unknown
Product essential addons for elementor
Published Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for unknown essential addons for elementor

Be the first to know when new unknown vulnerabilities affecting unknown essential addons for elementor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Essential Addons for Elementor
5.8.6 < 6.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/2982ee81-3a85-435b-8347-a7848e99f373/

Credits

Jakub Herman WPScan