Privilege Escalation Vulnerability in Essential Addons for Elementor by WordPress
CVE-2026-5193

6.5MEDIUM

What is CVE-2026-5193?

The Essential Addons for Elementor plugin for WordPress is susceptible to a privilege escalation issue affecting all versions up to and including 6.5.13. This vulnerability stems from inadequate role validation within the 'register_user' function, which fails to appropriately restrict user role creation, allowing authenticated users with author level access or higher to create new accounts with elevated privileges, such as editor. As a result, this poses a significant risk for unauthorized access and potential alterations to website content.

Affected Version(s)

Essential Addons for Elementor – Popular Elementor Templates & Widgets 0 <= 6.5.13

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
.