PT-2026-42071 · WordPress · Easy Elements For Elementor

Ankit Patel

·

Published

2026-05-20

·

Updated

2026-05-20

·

CVE-2026-7284

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Easy Elements for Elementor – Addons & Website Templates versions prior to 1.4.5
Description The plugin allows unauthenticated attackers to gain administrator access to a site through privilege escalation during user registration. This occurs because the easyel handle register() function fails to restrict the user roles that can be assigned during the registration process, enabling an attacker to specify the administrator role.
Recommendations Update the plugin to a version later than 1.4.4. As a temporary workaround, restrict access to the user registration functionality until the update is applied.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7284

Affected Products

Easy Elements For Elementor