CVE-2026-18039 PUBLISHED

Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment

Assigner: WPScan
Reserved: 28.07.2026 Published: 14.08.2026 Updated: 14.08.2026

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.

Product Status

Vendor Unknown
Product Essential Addons for Elementor
Versions Default: unaffected
  • affected from 5.8.6 to 6.7.2 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE