CVE-2026-18039: Essential Addons for Elementor Enables Admin Takeover

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/5 · Initial Access

An unauthenticated attacker uses the public registration form of the WordPress site as the entry point.

T1190 – Exploit Public-Facing Application
  • No prior access or login required
  • Affected: plugin Essential Addons for Elementor before version 6.7.2
  • Over 2 million active installations as potential attack surface
PHASE 2/5 · Execution

The attacker submits manipulated input containing reserved account attributes via the registration flow.

T1190 – Exploit Public-Facing Application
  • Exploitation of CVE-2026-18039 (CVSS 3.1 score 8.1, high)
  • Abuses a specific configuration of custom profile fields
  • Reserved account attributes are overwritten during registration
PHASE 3/5 · Privilege Escalation

By manipulating the user role, the attacker directly creates an administrator account.

T1068 – Exploitation for Privilege Escalation
  • Protected user role can be freely set up to administrator
  • Privilege escalation via uncontrolled account attributes
  • Any role selectable instead of subscriber or customer account
PHASE 4/5 · Persistence

The self-created administrator account gives the attacker persistent, legitimate access.

T1136.001 – Create Account: Local Account
  • New admin account survives sessions and basic cleanups
  • Detectable as unknown administrator accounts under Users → All Users
  • Attack can be automated and repeated at scale
PHASE 5/5 · Impact

With administrator privileges the attacker can fully take over the entire website.

T1505.003 – Server Software Component: Web Shell
  • Modify and delete content, create additional accounts
  • Install plugins and inject malicious code
  • Full control over the WordPress website
Short & clear answers
Frequently asked questions about this incident
Am I affected by the CVE-2026-18039 vulnerability?
Affected are websites running the Essential Addons for Elementor plugin in a version below 6.7.2 that use a specific configuration of custom profile fields. Check the displayed version number under Plugins → Installed Plugins. If it is below 6.7.2 (e.g. 6.7.1 or older), your installation is considered potentially vulnerable.
What exactly do I need to do now?
First create a full backup of your website files and database. Then update Essential Addons for Elementor to version 6.7.2 or newer and verify the version number afterwards. Finally, review your user accounts and delete any unknown or unauthorized administrator accounts.
How dangerous is this vulnerability really?
The vulnerability is rated as high with a CVSS 3.1 score of 8.1. An unauthenticated attacker can create an account with administrator rights via the regular registration form, gaining full control over the website. The combination of 'no login required' and targeting 'the highest possible privileges' makes it especially critical.
Is the vulnerability already being actively exploited?
Based on the available information, it is unknown whether the vulnerability is already being actively exploited. This is not an all-clear, however: once a vulnerability is publicly documented, attacker interest typically rises. Do not wait for confirmed attacks—implement the protective measures immediately.
Do I have to report this incident under the GDPR?
If an attacker gains administrator rights through this vulnerability, they potentially have access to all stored personal data such as customer or order information. Such unauthorized access may constitute a reportable personal data breach under the GDPR. In a real incident, review your notification and documentation obligations.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.