The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function, which only blocks the 'administrator' role. This makes it possible for authenticated attackers, with author level access and above, to create new user accounts with elevated privileges such as editor.
Metrics
Affected Vendors & Products
References
History
Thu, 14 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpdevteam Wpdevteam essential Addons For Elementor – Popular Elementor Templates & Widgets |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpdevteam Wpdevteam essential Addons For Elementor – Popular Elementor Templates & Widgets |
Thu, 14 May 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.5.13. This is due to insufficient role validation in the 'register_user' function, which only blocks the 'administrator' role. This makes it possible for authenticated attackers, with author level access and above, to create new user accounts with elevated privileges such as editor. | |
| Title | Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_user | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-14T10:45:23.691Z
Reserved: 2026-03-30T21:18:50.734Z
Link: CVE-2026-5193
Updated: 2026-05-14T10:45:19.161Z
Status : Received
Published: 2026-05-14T07:16:19.977
Modified: 2026-05-14T07:16:19.977
Link: CVE-2026-5193
No data.
OpenCVE Enrichment
Updated: 2026-05-14T10:00:12Z