PoC Index

CVE-2026-18039

HIGH 8.1EPSS 0.3%

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.

CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.28% chance of exploitation in the next 30 days, 20th percentile
Published
2026-08-14

Proof-of-concept exploits (1)

References

Related