Privilege Escalation in Easy Elements for Elementor Plugin by WordPress
CVE-2026-9018
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 May 2026
What is CVE-2026-9018?
The Easy Elements for Elementor plugin for WordPress is susceptible to a privilege escalation vulnerability. Unauthenticated attackers can exploit the easyel_handle_register() function in all versions up to and including 1.4.5. By manipulating the custom_meta POST array, attackers can overwrite the wp_capabilities meta key during user registration, potentially granting administrator-level access. This exploitation requires enabled user registration and the presence of the Login/Register widget, which indicates that the necessary nonce is available to unauthorized users.
Affected Version(s)
Easy Elements for Elementor β Addons & Website Templates 0 <= 1.4.5