CVE-2026-18039

NONE
Updated Aug 14, 2026
WordPress
Parameter Value
Affected Versions before 6.7.2
Vendor WordPress
Public PoC No

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.