CVE-2026-56028 is a critical unauthenticated privilege escalation vulnerability in the Easy Elements for Elementor – Addons & Website Templates WordPress plugin by themewant, affecting all versions up to and including 1.4.9. With a CVSS score of 9.8 (Critical), the flaw allows any unauthenticated remote attacker to create a WordPress account with full administrator privileges, leading to complete site takeover with no credentials or user interaction required.
