CVE-2023-41955
The Essential Addons for Elementor plugin for WordPress through version 5.8.8 allows privilege escalation because it does not properly control access to registration form creation and custom role assignment functionality within Elementor pages. An attacker with Elementor page builder access can create a registration form that defaults to assigning the administrator role, then use this form to register an account with administrative privileges. The vulnerability requires publishing capabilities to exploit and represents a reintroduction of a flaw that was previously fixed in version 4.6.5.
Based on public CVE data (MITRE/NVD).