CVE-2026-18039: Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment
The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/essential-addons-for-elementorto a version that resolves this vulnerability.Fixed in 6.7.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18039?
CVE-2026-18039 has a risk score of 80, indicating a high severity level.
How do I fix CVE-2026-18039?
To fix CVE-2026-18039, update the Essential Addons for Elementor plugin to version 6.7.2 or later.
What vulnerabilities does CVE-2026-18039 exploit?
CVE-2026-18039 exploits a lack of validation on user-supplied registration fields, leading to privilege escalation.
What are the potential consequences of CVE-2026-18039?
The potential consequences of CVE-2026-18039 include allowing unauthenticated attackers to register accounts with elevated privileges, such as administrator.
Which software is affected by CVE-2026-18039?
CVE-2026-18039 affects the Essential Addons for Elementor WordPress plugin before version 6.7.2.