CyberRota Analysis
AI-GeneratedThe Essential Addons for Elementor WordPress plugin prior to version 6.7.2 is vulnerable due to improper handling of user-supplied registration fields, which can be exploited by unauthenticated attackers to create accounts with arbitrary roles, including administrator. This poses a significant risk to WordPress sites that utilize custom profile fields, as it could lead to unauthorized access and control over the site. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.
Original NVD Description
The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.