What is CVE-2026-18039?
A vulnerability in the Essential Addons for Elementor plugin before version 6.7.2 allows user-supplied registration fields to overwrite reserved account attributes. This enables unauthenticated attackers to register accounts with arbitrary roles, including administrator, on affected sites. Immediate plugin update is strongly recommended.
Azərbaycanca: Essential Addons for Elementor plaginində 6.7.2 versiyasından əvvəl zəiflik aşkarlanıb. İstifadəçi qeydiyyatı zamanı təqdim olunan məlumatlar qorunan hesab atributlarını (məsələn, administrator rolu) ləğv edə bilər, bu da autentifikasiya olunmamış hücumçulara yüksək imtiyazlı hesab yaratmağa imkan verir. Dərhal plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of the Essential Addons for Elementor plugin are affected by CVE-2026-18039?
The vulnerability affects all versions of the Essential Addons for Elementor plugin before version 6.7.2.
What privileged action can an attacker perform via the CVE-2026-18039 vulnerability?
Unauthenticated attackers can register accounts with arbitrary roles, including administrator, by overwriting reserved account attributes during registration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.