Impact
The Essential Addons for Elementor WordPress plugin before 6.7.2 fails to block user‑supplied registration fields from overriding reserved account attributes, enabling an attacker to register an account with any role, including administrator. This flaw allows the attacker to gain full administrative control over the site, compromising confidentiality, integrity, and availability. The vulnerability arises from missing validation of field names during account creation.
Affected Systems
Any WordPress site that runs Essential Addons for Elementor older than 6.7.2 and has a custom profile field with a label tied to a reserved account attribute is affected. Many sites that use Elementor themes and incorporate this plugin fit that criterion.
Risk and Exploitability
The attack requires no authentication and can be carried out through the public user registration endpoint. Based on the description, an attacker could submit a crafted profile field via the public registration page to obtain an arbitrary role. The EPSS score is < 1%, indicating a low probability of exploitation, while the CVSS score of 8.1 classifies the vulnerability as high severity. The vulnerability is not listed in the CISA KEV catalog. Because the exploit relies only on form input, it should be considered high‑risk by security teams.
OpenCVE Enrichment