Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-56028 – Unauthenticated Privilege Escalation – Easy Elements for Elementor WordPress Plu…

Be the first to know when new zero-days emerge:

Summary

CVE-2026-56028 is a critical unauthenticated privilege escalation vulnerability in the Easy Elements for Elementor – Addons & Website Templates WordPress plugin by themewant, affecting all versions up to and including 1.4.9. With a CVSS score of 9.8 (Critical), the flaw allows any unauthenticated remote attacker to create a WordPress account with full administrator privileges, leading to complete site takeover with no credentials or user interaction required.

Technical details

  • Root cause: The plugin’s AJAX-based registration handler processes attacker-supplied user metadata without any key whitelist or blocklist validation. By passing crafted values through the custom_meta POST parameter, an attacker can cause update_user_meta() to overwrite the wp_capabilities database entry for a newly registered user, assigning them administrator-level capabilities (CWE-266: Incorrect Privilege Assignment).
  • Trigger conditions: WordPress user registration must be enabled on the target site, and at least one publicly accessible page must render the plugin’s Login/Register widget. The registration nonce (easy_elements_nonce) is exposed in the page DOM and is retrievable without authentication, removing any effective barrier to exploitation.
  • Attack vector: Fully remote and unauthenticated — exploitable over the network by any attacker who can reach the WordPress site’s front end. No special knowledge of the target environment is required beyond the presence of the widget.
  • Impact: Upon successful exploitation, the attacker gains a WordPress administrator account, granting complete control over the site: installing or modifying plugins and themes, creating backdoors, accessing all stored data, and pivoting to the underlying server depending on hosting configuration (Confidentiality: High / Integrity: High / Availability: High).
  • Relationship to CVE-2026-9018: A prior vulnerability in the same plugin (CVE-2026-9018, affecting versions ≤ 1.4.5) was rooted in the same class of flaw in the same registration handler. Users who previously patched by upgrading to versions 1.4.6–1.4.9 remain vulnerable to CVE-2026-56028, as the underlying issue was not fully remediated until version 1.5.0.

Affected software

  • Easy Elements for Elementor – Addons & Website Templates (WordPress plugin by themewant), versions ≤ 1.4.9

Severity

  • CVSS v3.1 Base Score: 9.8 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • CWE: CWE-266 – Incorrect Privilege Assignment

Mitigation and recommended actions

  • Immediate action: Update the Easy Elements for Elementor plugin to version 1.5.0 or later. The vendor released the security fix in version 1.5.0 (June 17, 2026); the current release is 1.5.1 (June 18, 2026). Both versions resolve this vulnerability.
  • If immediate patching is not possible:
    • Disable WordPress user registration (Settings → General → Membership) until the plugin can be updated.
    • Remove or unpublish any pages containing the plugin’s Login/Register widget to eliminate the exposed attack surface.
    • Apply web application firewall (WAF) rules to block crafted custom_meta POST parameters targeting the plugin’s AJAX registration endpoint.
  • Verify remediation: After updating, confirm the installed plugin version is 1.5.0 or higher via the WordPress admin dashboard (Plugins → Installed Plugins).

IONIX Status

The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge