CVE-2026-18039

CVE-2026-18039: Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment

Vendor Unknown
Product Essential Addons for Elementor
Published August 14, 2026
Last update August 14, 2026

CVSS base score

What the vulnerability does

01Description

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.

Key dates

02Disclosure timeline

August 14, 2026 CVE published
August 14, 2026 Record updated