Privilege Escalation in Easy Elements for Elementor Plugin by WordPress
CVE-2026-7284
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 May 2026
What is CVE-2026-7284?
The Easy Elements for Elementor β Addons & Website Templates plugin for WordPress contains a vulnerability that allows for privilege escalation through its user registration process. This issue arises from the 'easyel_handle_register' function, which fails to restrict the user roles that can be assigned during registration. As a result, unauthenticated attackers could exploit this by registering a new user account with the 'administrator' role, effectively granting them full administrative access to the website.
Affected Version(s)
Easy Elements for Elementor β Addons & Website Templates 0 <= 1.4.4