CVE-2026-18039
WordPress Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-18039 is an unauthenticated privilege escalation vulnerability in the Essential Addons for Elementor WordPress plugin, classified as a mass assignment / improper privilege management flaw (CWE-269). It allows unauthenticated attackers to register a WordPress account with an arbitrary role — including administrator — on sites where a custom profile field with a particular label has been configured. Affected versions span from 5.8.6 up to (but not including) 6.7.2, developed by WPDeveloper. The vulnerability was publicly disclosed on August 12, 2026, and assigned CVE-2026-18039 on August 14, 2026. WPScan rates it CVSS 8.1 (High) (WPScan, Github Advisory).

Détails techniques

The root cause is a mass assignment vulnerability (CWE-269: Improper Privilege Management) in the plugin's user registration flow. The plugin fails to sanitize or block user-supplied registration field values from overwriting reserved WordPress account attributes such as the user role. When a site administrator has configured a custom profile field with a specific label (the exact label is withheld pending PoC disclosure on September 12, 2026), an unauthenticated attacker can submit a crafted registration request that sets the role attribute to administrator or any other privileged role. This is a server-side input validation failure — the plugin does not maintain a blocklist or allowlist of protected account attributes during registration field processing (WPScan).

Impact

Successful exploitation grants an unauthenticated attacker full administrator access to the affected WordPress site, enabling complete site takeover. With administrator privileges, an attacker can install malicious plugins or themes, exfiltrate sensitive data (user credentials, personal information, payment data), deface the site, establish persistent backdoors, or use the compromised site as a launchpad for further attacks against site visitors or connected infrastructure. The impact is limited to sites that have configured a custom profile field with the specific vulnerable label, but on those sites the confidentiality, integrity, and availability of the entire WordPress installation are fully compromised (WPScan, Github Advisory).

Exploitabilité

As of the disclosure date, there is no public proof-of-concept exploit available; WPScan has withheld the PoC until September 12, 2026, to allow time for patching (WPScan). There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is reported as 0.0, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory). However, the unauthenticated nature of the attack and the high privilege gain make this a high-value target once the PoC is released.

Étapes d’exploitation

  1. Reconnaissance: Identify WordPress sites running Essential Addons for Elementor versions 5.8.6 through 6.7.1 using tools like WPScan, Shodan, or by inspecting plugin metadata in page source (/wp-content/plugins/essential-addons-for-elementor-lite/).
  2. Identify vulnerable configuration: Confirm the target site has a custom profile registration form built with the Essential Addons for Elementor plugin that includes a custom field with the specific vulnerable label (exact label withheld until September 12, 2026).
  3. Craft malicious registration request: Submit a POST request to the site's registration endpoint (typically handled by the plugin's AJAX handler) with standard registration fields plus an additional parameter that sets the role attribute to administrator.
  4. Overwrite reserved attribute: Because the plugin does not block user-supplied values from overwriting reserved account attributes, the submitted role value is accepted and applied during account creation.
  5. Achieve administrator access: Log in with the newly registered account, which now holds administrator privileges, granting full control over the WordPress site (WPScan).

Indicateurs de compromis

  • Logs: WordPress wp-login.php and registration logs showing new user accounts created with the administrator role from unexpected IP addresses; PHP error logs or access logs showing unusual POST requests to plugin AJAX endpoints (e.g., wp-admin/admin-ajax.php with action parameters related to Essential Addons registration).
  • Database: Unexpected entries in the wp_users and wp_usermeta tables with wp_capabilities set to administrator for recently registered accounts with no corresponding legitimate sign-up activity.
  • File System: New or modified plugin/theme files, unexpected PHP files in wp-content/uploads/ or plugin directories, or new cron jobs — indicative of post-exploitation activity following privilege escalation.
  • Network: Outbound connections from the web server to unknown external IPs shortly after new administrator account creation, potentially indicating backdoor installation or data exfiltration.

Atténuation et solutions de contournement

The primary remediation is to update the Essential Addons for Elementor plugin to version 6.7.2 or later, which contains the fix for this vulnerability (WPScan). As an interim workaround, administrators should audit all custom profile fields configured in the plugin and identify any fields with labels that could map to reserved WordPress account attributes, then disable or reconfigure those fields. Additionally, monitor the WordPress user database for any newly registered accounts with unexpected administrator roles, and consider temporarily disabling the plugin's user registration functionality if it is not business-critical until the update can be applied.

Réactions de la communauté

The vulnerability was discovered and reported by researcher Jakub Herman (jakubherman.net) and submitted to WPScan (WPScan). The offseq security account on Mastodon (infosec.exchange) noted the vulnerability shortly after disclosure. No major vendor statements or widespread media coverage have been identified beyond the standard advisory publications.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté WordPress Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-18039NONEN/A
  • essential-addons-for-elementor-lite
NonOuiAug 14, 2026
CVE-2026-16810NONEN/A
  • bit-form
NonOuiAug 14, 2026
CVE-2026-16739NONEN/A
  • epeken-all-kurir
NonNonAug 14, 2026
CVE-2026-15205NONEN/A
  • paymob-for-woocommerce
NonOuiAug 14, 2026
CVE-2026-14290NONEN/A
  • embed-google-photos-album-easily
NonNonAug 14, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités