
PEACH
Un cadre d’isolation des locataires
CVE-2026-18039 is an unauthenticated privilege escalation vulnerability in the Essential Addons for Elementor WordPress plugin, classified as a mass assignment / improper privilege management flaw (CWE-269). It allows unauthenticated attackers to register a WordPress account with an arbitrary role — including administrator — on sites where a custom profile field with a particular label has been configured. Affected versions span from 5.8.6 up to (but not including) 6.7.2, developed by WPDeveloper. The vulnerability was publicly disclosed on August 12, 2026, and assigned CVE-2026-18039 on August 14, 2026. WPScan rates it CVSS 8.1 (High) (WPScan, Github Advisory).
The root cause is a mass assignment vulnerability (CWE-269: Improper Privilege Management) in the plugin's user registration flow. The plugin fails to sanitize or block user-supplied registration field values from overwriting reserved WordPress account attributes such as the user role. When a site administrator has configured a custom profile field with a specific label (the exact label is withheld pending PoC disclosure on September 12, 2026), an unauthenticated attacker can submit a crafted registration request that sets the role attribute to administrator or any other privileged role. This is a server-side input validation failure — the plugin does not maintain a blocklist or allowlist of protected account attributes during registration field processing (WPScan).
Successful exploitation grants an unauthenticated attacker full administrator access to the affected WordPress site, enabling complete site takeover. With administrator privileges, an attacker can install malicious plugins or themes, exfiltrate sensitive data (user credentials, personal information, payment data), deface the site, establish persistent backdoors, or use the compromised site as a launchpad for further attacks against site visitors or connected infrastructure. The impact is limited to sites that have configured a custom profile field with the specific vulnerable label, but on those sites the confidentiality, integrity, and availability of the entire WordPress installation are fully compromised (WPScan, Github Advisory).
As of the disclosure date, there is no public proof-of-concept exploit available; WPScan has withheld the PoC until September 12, 2026, to allow time for patching (WPScan). There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is reported as 0.0, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory). However, the unauthenticated nature of the attack and the high privilege gain make this a high-value target once the PoC is released.
/wp-content/plugins/essential-addons-for-elementor-lite/).role attribute to administrator.role value is accepted and applied during account creation.wp-login.php and registration logs showing new user accounts created with the administrator role from unexpected IP addresses; PHP error logs or access logs showing unusual POST requests to plugin AJAX endpoints (e.g., wp-admin/admin-ajax.php with action parameters related to Essential Addons registration).wp_users and wp_usermeta tables with wp_capabilities set to administrator for recently registered accounts with no corresponding legitimate sign-up activity.wp-content/uploads/ or plugin directories, or new cron jobs — indicative of post-exploitation activity following privilege escalation.The primary remediation is to update the Essential Addons for Elementor plugin to version 6.7.2 or later, which contains the fix for this vulnerability (WPScan). As an interim workaround, administrators should audit all custom profile fields configured in the plugin and identify any fields with labels that could map to reserved WordPress account attributes, then disable or reconfigure those fields. Additionally, monitor the WordPress user database for any newly registered accounts with unexpected administrator roles, and consider temporarily disabling the plugin's user registration functionality if it is not business-critical until the update can be applied.
The vulnerability was discovered and reported by researcher Jakub Herman (jakubherman.net) and submitted to WPScan (WPScan). The offseq security account on Mastodon (infosec.exchange) noted the vulnerability shortly after disclosure. No major vendor statements or widespread media coverage have been identified beyond the standard advisory publications.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."