Impact
The Royal Elementor Addons WordPress plugin before version 1.7.1067 fails to escape user supplied form data. As attacker can inject arbitrary HTML that will be rendered by any client that receives the email. This flaw can lead to phishing attacks or other malicious payload delivery to site administrators via email, compromising the confidentiality and integrity of communications.
Affected Systems
The vulnerability affects the Royal Elementor Addons WordPress plugin, sold under the vendor name Royal Addons for Elementor, for all revisions earlier than 1.7.1067. Only plugins matching that vendor and product with an older version are impacted; no other WordPress components are affected.
Risk and Exploitability
The flaw has a CVSS score of 6.1, indicating a moderate severity. The EPSS score is less than 1%, suggesting that the exploitation probability is low, and it is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated web request to the form widget; an attacker submits a crafted payload and the plugin sends the compromised email to the site administrator. Because the issue involves email notification rather than direct web output, visible exploitation may require knowledge of the target’s email system but remains feasible for attackers who control the plugin input.
OpenCVE Enrichment