CVE-2026-0673
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Summary
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the element_pack_contact_form AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email headers. This makes it possible for unauthenticated attackers to inject arbitrary email headers into emails sent by the contact form.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| bdthemes | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons | 0 <= 8.3.15 | affected |
Weaknesses
- CWE-93: CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/941d0647-5027-4642-88fc-3ab26acbb639?source=cve
- https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/tags/8.3.16/modules/contact-form/module.php?marks=209#L209
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.