Impact
Element Pack Addons for Elementor includes a contact form that processes input via the element_pack_contact_form AJAX action. The plugin fails to sanitize newline characters in user-supplied fields, allowing an attacker to inject arbitrary email headers. Because no authentication is required to access the endpoint, the attacker can add headers such as Subject, To, or Reply-To, potentially forging the sender address or enabling phishing or spam from the site. The injected headers compromise email integrity and may lead to reputational damage or malicious phishing emails sent from the domain.
Affected Systems
All WordPress installations that have the Element Pack Addons for Elementor plugin version 8.3.15 or earlier are affected. This includes the Elementor Widgets, Elementor Templates, and Elementor Addons components for these versions. Versions beyond 8.3.15 are not impacted.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported yet. The attack requires only the ability to submit a request to the AJAX endpoint, meaning it can be performed from any external location without authentication, posing a medium to high risk if the contact form is publicly exposed.
OpenCVE Enrichment