What the vulnerability does
01Description
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user.
Explanation of Vulnerability in Simple Terms
02Summary
Essential Addons for Elementor versions up to 4.6.4 lack proper authorization checks, allowing authenticated users with low privileges to perform actions restricted to administrators. An attacker with a basic user account can read sensitive data, modify site content, or disrupt service. Update to a version newer than 4.6.4 immediately.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify content, or disrupt the site using a low-privilege user account.
Potential impact on your site
04Site Impact
Any registered user can perform admin-level actions on Elementor pages and settings.
Conditions required to exploit
05Prerequisites
Attacker needs a valid low-privilege user account on the WordPress site.
Key dates
06Disclosure timeline
October 16, 2024
CVE published
April 8, 2026
Record updated