CVE-2026-18039: CWE-269 Improper Privilege Management in Essential Addons for Elementor
A vulnerability in the Essential Addons for Elementor WordPress plugin before version 6.7.2 allows unauthenticated attackers to register accounts with arbitrary roles, including administrator, by exploiting improper privilege management. This occurs when user-supplied registration fields overwrite reserved account attributes on sites with a custom profile field configured with a specific label.
AI Analysis
Technical Summary
CVE-2026-18039 is an improper privilege management vulnerability (CWE-269) in the Essential Addons for Elementor WordPress plugin. Versions prior to 6.7.2 do not properly restrict user-supplied registration fields, enabling unauthenticated attackers to overwrite reserved account attributes. This flaw allows attackers to register accounts with arbitrary roles, including administrative privileges, on sites that have a custom profile field with a particular label configured. No CVSS score or official remediation level is provided, and no known exploits are reported in the wild.
Potential Impact
Successful exploitation allows unauthenticated attackers to gain elevated privileges by registering accounts with arbitrary roles, including administrator. This can lead to full site compromise on affected WordPress installations using vulnerable plugin versions with the specific custom profile field configuration.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should consider disabling user registration or removing the vulnerable custom profile field configuration to mitigate risk.
CVE-2026-18039: CWE-269 Improper Privilege Management in Essential Addons for Elementor
Description
A vulnerability in the Essential Addons for Elementor WordPress plugin before version 6.7.2 allows unauthenticated attackers to register accounts with arbitrary roles, including administrator, by exploiting improper privilege management. This occurs when user-supplied registration fields overwrite reserved account attributes on sites with a custom profile field configured with a specific label.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-18039 is an improper privilege management vulnerability (CWE-269) in the Essential Addons for Elementor WordPress plugin. Versions prior to 6.7.2 do not properly restrict user-supplied registration fields, enabling unauthenticated attackers to overwrite reserved account attributes. This flaw allows attackers to register accounts with arbitrary roles, including administrative privileges, on sites that have a custom profile field with a particular label configured. No CVSS score or official remediation level is provided, and no known exploits are reported in the wild.
Potential Impact
Successful exploitation allows unauthenticated attackers to gain elevated privileges by registering accounts with arbitrary roles, including administrator. This can lead to full site compromise on affected WordPress installations using vulnerable plugin versions with the specific custom profile field configuration.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should consider disabling user registration or removing the vulnerable custom profile field configuration to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-28T08:45:17.480Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7eb1a0bf8831d5398754c3
Added to database: 08/14/2026, 06:11:44 UTC
Last enriched: 08/14/2026, 06:30:30 UTC
Last updated: 08/14/2026, 07:11:22 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.