The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on form submission.
References
Configurations
No configuration.
History
16 Sep 2026, 18:17
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-116 |
Information
Published : 2026-09-16 07:16
Updated : 2026-09-16 20:25
NVD link : CVE-2026-13407
Mitre link : CVE-2026-13407
CVE.ORG link : CVE-2026-13407
JSON object : View
Products Affected
No product.
CWE
CWE-116
Improper Encoding or Escaping of Output
