AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-18039

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Essential Addons for Elementor WordPress plugin prior to version 6.7.2 is vulnerable due to improper handling of user-supplied registration fields, which can be exploited by unauthenticated attackers to create accounts with arbitrary roles, including administrator. This poses a significant risk to WordPress sites that utilize custom profile fields, as it could lead to unauthorized access and control over the site. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.

CVE
CVE-2026-18039
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
WordPress

Original NVD Description

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.