CVE-2026-13407

The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on form submission.
Configurations

No configuration.

History

16 Sep 2026, 18:17

Type Values Removed Values Added
CWE CWE-116

Information

Published : 2026-09-16 07:16

Updated : 2026-09-16 20:25


NVD link : CVE-2026-13407

Mitre link : CVE-2026-13407

CVE.ORG link : CVE-2026-13407


JSON object : View

Products Affected

No product.

CWE
CWE-116

Improper Encoding or Escaping of Output