Sceawere

Vulnerability Detail

CVE-2026-18039UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Essential Addons for Elementor Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
12h ago
Vendor
Unknown
Product
Essential Addons for Elementor
Attack Type
CWE-269 Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-14T06:17:09.077Z",
  "pubdate": "2026-08-14T06:17:09.077Z",
  "executiveSummary": "The Essential Addons for Elementor WordPress plugin before version 6.7.2 suffers from an improper input validation and attribute assignment vulnerability within its user registration functionality.\nThis security flaw enables unauthenticated malicious actors to register accounts with arbitrary administrative privileges by supplying crafted registration fields that overwrite reserved internal account attributes.\nThe root cause stems from the application failing to sanitize or restrict user-supplied parameters during the registration process, allowing external input to map directly to core user metadata fields if a specific custom profile field configuration is present.\nThe impact of successful exploitation is critical, as it grants complete administrative control over the underlying WordPress site to an unauthenticated external attacker, leading to potential remote code execution, data exfiltration, and full infrastructure compromise.\nExploitation requires the target WordPress instance to have user registration enabled alongside a specific custom profile field configured with a particular label.\nOrganizations utilizing affected versions of the product face severe risk implications and must apply immediate remediation controls to prevent unauthorized privilege escalation vectors.",
  "technicalDetails": "The vulnerability resides in the user registration mechanism of the Essential Addons for Elementor WordPress plugin, affecting all versions prior to 6.7.2.\nThe root cause of the flaw is the insecure handling of user-supplied registration fields, where the input processing logic fails to implement adequate whitelist validation or attribute filtering.\nConsequently, incoming POST parameters corresponding to user-supplied registration fields can directly overwrite reserved internal account attributes and user meta values during the account creation lifecycle.\nAuthentication requirements are absent, meaning an unauthenticated remote attacker can trigger the vulnerable code path over the network.\nPrivilege requirements are nonexistent prior to exploitation, but successful payload execution elevates the attacker's session to administrator privileges.\nThe exploitation prerequisites dictate that the targeted WordPress site must permit user registration and must have a custom profile field configured with a particular label recognized by the plugin's registration handler.\nThe attack flow proceeds as follows: First, the unauthenticated attacker identifies a vulnerable WordPress instance running Essential Addons for Elementor prior to version 6.7.2 with the requisite custom profile field configuration enabled.\nSecond, the attacker crafts an HTTP registration request containing malicious parameters injected into the user-supplied registration fields.\nThird, the plugin processes the input without validating whether the supplied keys correspond to restricted internal attributes, such as user roles or capabilities.\nFourth, the underlying database record for the newly registered user is instantiated with the injected payload values, successfully mapping the user role attribute to administrator.\nFinally, the attacker authenticates using the newly created credentials, achieving full administrative access and completing the post-exploitation takeover of the WordPress application."
}
CVE-2026-18039: Essential Addons for Elementor Privilege Escalation (HIGH Severity, CVSS: 8.1) - Sceawere