GHSA-74gv-xjcv-gwc2MediumCVSS 5.3
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header...
🔗 CVE IDs covered (1)
📋 Description
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the element_pack_contact_form AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email headers. This makes it possible for unauthenticated attackers to inject arbitrary email headers into emails sent by the contact form.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-0673
- https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/tags/8.3.16/modules/contact-form/module.php?marks=209#L209
- https://www.wordfence.com/threat-intel/vulnerabilities/id/941d0647-5027-4642-88fc-3ab26acbb639?source=cve
- https://github.com/advisories/GHSA-74gv-xjcv-gwc2