CVE 9.8 CRITICAL

Easy Elements for Elementor <= 1.4.4 - Unauthenticated Privilege Escalation via easyel_handle_register_CVE-2026-7284

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

AI Analysis

Unauthenticated privilege escalation via user registration due to the 'easyel_handle_register' function not restricting user roles.

Basic Information

ID CVE-2026-7284
Source Wordfence
Published May 20, 2026 at 01:25

Affected Product

Vendor themewant
Product Easy Elements for Elementor – Addons & Website Templates
Affected Versions themewant Easy Elements for Elementor – Addons & Website Templates 0

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor themewant
Product Easy Elements for Elementor – Addons & Website Templates
Version 1.4.4

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.