Executive brief
A vulnerability in the Easy Elements plugin for WordPress allows unauthorized individuals to create new accounts with full administrator privileges. This plugin is used to add custom design elements and templates to WordPress websites. By exploiting this flaw, an attacker can take complete control of a website, potentially leading to data theft, site defacement, or the installation of malicious software.
Technical details
The Easy Elements for Elementor plugin suffers from a privilege escalation vulnerability due to improper input validation in the 'easyel_handle_register' function. The function fails to restrict the user roles that can be assigned during the registration process. An unauthenticated remote attacker can exploit this by submitting a registration request that explicitly includes the 'administrator' role. Successful exploitation grants the attacker full administrative access to the WordPress environment. The issue affects all versions up to 1.4.4; users should update to a patched version if available.
Affected products
- Easy Elements Easy Elements for Elementor – Addons & Website Templates Up to, and including, 1.4.4
Timeline
- 2026-05-20: disclosed: Initial disclosure of the vulnerability.