PT-2026-42071 · WordPress · Easy Elements For Elementor
Ankit Patel
·
Published
2026-05-20
·
Updated
2026-05-20
·
CVE-2026-7284
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Easy Elements for Elementor – Addons & Website Templates versions prior to 1.4.5
Description
The plugin allows unauthenticated attackers to gain administrator access to a site through privilege escalation during user registration. This occurs because the
easyel handle register() function fails to restrict the user roles that can be assigned during the registration process, enabling an attacker to specify the administrator role.Recommendations
Update the plugin to a version later than 1.4.4.
As a temporary workaround, restrict access to the user registration functionality until the update is applied.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easy Elements For Elementor