Published on 15 August 2026
An unauthenticated attacker who obtains an account with administrator privileges through your website's perfectly ordinary registration form – that's the scenario warned about in a security advisory published on 14 August 2026. Affected is the popular WordPress plugin Essential Addons for Elementor in all versions before 6.7.2. With more than two million active installations, it ranks among the most widely used extensions for the page builder Elementor. If you run one of these websites, you should read this article to the end – and then act.
Under the identifier CVE-2026-18039, a serious security vulnerability in Essential Addons for Elementor has been made public. CVE numbers (short for "Common Vulnerabilities and Exposures") are internationally standardised catalogue numbers for known vulnerabilities – they ensure that everyone involved is talking about the same flaw.
The core of the problem: with a certain configuration of custom profile fields – that is, additional input fields you can define yourself in the registration or profile form – it is possible for an unauthenticated attacker to overwrite reserved account attributes during registration. Reserved attributes are internal properties of a user account that should actually be protected – this includes, in particular, the assigned user role.
It is precisely this role that can be manipulated through the vulnerability. Instead of an ordinary subscriber or customer account, an attacker can use it to create an account with any role, up to and including administrator. In practice, an administrator account means complete control over the WordPress website.
The vulnerability was documented by the security service FreshySites in a security bulletin. According to the industry-standard rating system CVSS in version 3.1, the severity is given a score of 8.1 and is therefore classified as high. The CVSS score is a standardised metric from 0 to 10 that reflects the severity of a vulnerability – values from 7.0 are considered high, from 9.0 critical.
To put the scale into context, it's worth looking at what makes an attack particularly attractive or dangerous. Two factors combine in CVE-2026-18039:
The combination of "no login required" and "full control as the target" is why this class of vulnerabilities – so-called privilege escalation via uncontrolled account attributes – is especially prized by attackers.
Affected are websites that meet the following conditions:
The official WordPress plugin directory lists more than two million active installations for Essential Addons for Elementor. That doesn't mean all of these websites are vulnerable – the flaw takes hold under the configuration described – but it illustrates how large the potential attack surface is. With such a widely used extension, searching for exploitable targets is particularly worthwhile for criminals, because an attack that works once can be automated and repeated on a large scale.
Whether the vulnerability is already being actively exploited is unknown based on the available material. This is expressly not an all-clear: once a vulnerability has been publicly documented, experience shows that the interest of potential attackers rises. So you should not wait until attacks are confirmed, but implement the measures described below immediately.
Go through the following steps in order to determine whether your website needs action:
The most effective measure against CVE-2026-18039 is updating the plugin to a version in which the vulnerability is fixed. The material names version 6.7.2 as the release from which the vulnerability is no longer present in the affected versions "before 6.7.2". Proceed as follows:
If you don't want to carry out these steps yourself or are unsure, have them done by someone with WordPress experience or by your website support. The order matters: first backup, then update, then check the user accounts.
For companies in Germany, such a vulnerability has not only a technical but also a legal dimension. If an attacker obtains administrator privileges via CVE-2026-18039, they potentially have access to all personal data stored on the website – for example customer data, contact enquiries, account data of registered users or order information.
Such unauthorised access can constitute a personal data breach within the meaning of the General Data Protection Regulation. If an incident actually occurs, notification obligations may apply: a data breach must, as a rule, be reported to the competent supervisory authority within 72 hours of becoming aware of it, and under certain conditions the affected individuals must also be informed. Whether a notification obligation exists in a specific case depends on the concrete risk assessment.
In practical terms this means: whoever closes the gap now protects not only the operation of their own website, but also reduces the risk of a reportable data breach and the possible consequences associated with it. Document your protective measures – this includes the time at which the update was applied. Such documentation can, if the worst comes to the worst, prove that you fulfilled your duty of care.
The combination of a CVSS score of 8.1 ("high"), the possibility of obtaining an administrator account without any login, and the enormous prevalence of the plugin with over two million installations makes CVE-2026-18039 a vulnerability to be taken seriously. Even though active exploitation has not yet been confirmed, the rule holds: publicly documented flaws in widely used plugins quickly come into attackers' sights.
The damage scenario is clearly outlined – takeover of the entire website via a smuggled-in administrator account. The effort for protection, by contrast, is manageable: in most cases a swift update to version 6.7.2 or newer suffices, supplemented by a review of the existing user accounts. This ratio of low effort to high potential damage clearly argues for immediate action.
With CVE-2026-18039, operators of WordPress websites that use Essential Addons for Elementor in a version before 6.7.2 face a serious vulnerability: attackers can trick their way to an account with administrator privileges via the regular registration. With a plugin boasting more than two million installations, the potential attack surface is large.
The recommended course of action is unambiguous and can be summed up in one sentence: Update Essential Addons for Elementor immediately to version 6.7.2 or newer, back up your website beforehand and afterwards check your user accounts for unauthorised administrators. Also review the configuration of your custom profile fields. Do not wait to see whether attacks are confirmed – the vulnerability is publicly known, and closing it takes considerably less time than the clean-up work after a successful takeover.
Source: Security bulletin from FreshySites on CVE-2026-18039, published on 14 August 2026 (freshysites.com). This article is current as of: 15 August 2026.