{"id":"CVE-2026-9018","title":"The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function","summary":"The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"published":"2026-05-22","updated":"2026-07-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9018","references":[{"url":"https://plugins.trac.wordpress.org/browser/easy-elements/tags/1.4.5/includes/Utils/Enqueue.php#L200","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/easy-elements/tags/1.4.5/widgets/login-register/class.login-register.php#L128","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/easy-elements/tags/1.4.5/widgets/login-register/class.login-register.php#L65","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/easy-elements/tags/1.4.5/widgets/login-register/class.login-register.php#L9","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f1de4899-532a-4558-bff0-f4610bfdd49d?source=cve","label":"security@wordfence.com"}],"tags":["nvd","exploit-available"],"epss":0.00541,"epssPercentile":0.44212,"ingestedAt":"2026-07-23T11:17:34.028Z","exploits":{"github":1,"githubRepos":["https://github.com/xxconi/CVE-2026-9018"],"checkedAt":"2026-09-21T15:31:21.854Z"},"exploitAvailable":true,"slug":"CVE-2026-9018","body":"## Overview\n\nThe Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_nopriv_eel_register` AJAX handler iterating the attacker-controlled `custom_meta` POST array and writing every supplied key-value pair to the newly created user's meta via `update_user_meta()` without any key whitelist or blocklist, allowing the `wp_capabilities` user meta key to be overwritten after `wp_insert_user()` has already assigned a safe role. This makes it possible for unauthenticated attackers to register a new account with full administrator-level privileges by supplying `custom_meta[wp_capabilities][administrator]=1`. Exploitation requires that user registration is enabled on the site and that at least one page exposes the Login/Register widget, which publishes the required `easy_elements_nonce` into the page DOM where it can be retrieved by any unauthenticated visitor via a simple GET request.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5544,"id":"CVE-2026-9018","ts":1788887298534,"field":"exploit_available","old":"false","new":"true"},{"seq":4419,"id":"CVE-2026-9018","ts":1788886405011,"field":"exploit_available","old":"true","new":"false"},{"seq":3130,"id":"CVE-2026-9018","ts":1788883069808,"field":"exploit_available","old":"false","new":"true"},{"seq":2159,"id":"CVE-2026-9018","ts":1788882472863,"field":"exploit_available","old":"true","new":"false"},{"seq":1188,"id":"CVE-2026-9018","ts":1788881909688,"field":"exploit_available","old":"false","new":"true"}]}