CVE-2026-18039General

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-14: 2Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-14: 208-14
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-18039 The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, all… https://www.cve.org/CVERecord?id=CVE-2026-18039

    Post summary

    The text notes a flaw in Essential Addons for Elementor that permits overwriting reserved account attributes via user‑supplied registration fields, but it gives no PoC, exploit, patch, or active exploitation details.

    000101.5K
    57.9K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-18039 (CVSS 8.1): Essential Addons for Elementor <6.7.2 lets unauthenticated attackers overwrite reserved account attributes. Update plugin now if in use. https://nvd.nist.gov/vuln/deta… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/Fbdgh3J2WG

    Post summary

    The tweet announces CVE-2026-18039, a high‑severity flaw in Essential Addons for Elementor that allows unauthenticated account attribute overwrites, and urges users to update the plugin immediately.

    0000043
    92 followersView on X

Explore more