Executive brief
Easy Elements for Elementor is a WordPress plugin that provides additional design tools and templates for website building. A critical security flaw allows unauthorized individuals to gain administrative control over a website without needing a password. This could lead to complete site takeover, data theft, or the injection of malicious content.
Technical details
The Easy Elements for Elementor plugin (versions 1.4.9 and below) contains an unauthenticated privilege escalation vulnerability due to incorrect privilege assignment (CWE-266). An attacker can exploit this flaw over the network without any prior authentication or user interaction. By sending a crafted request, a malicious actor can escalate their privileges to an administrative level, potentially leading to full site compromise. The issue is resolved in version 1.5.0.
Affected products
- Themewant Easy Elements for Elementor – Addons & Website Templates <= 1.4.9
Timeline
- 2026-04-24: disclosed: Vulnerability reported by researcher Evan NR
- 2026-06-23: advisory: Patchstack published advisory details
- 2026-06-26: disclosed: CVE published to NVD dataset