Impact
The Essential Addons for Elementor Templates & Widgets plugin for WordPress contains a flaw that lets an authenticated user with Contributor or higher privileges inject a carriage‑return line feed (CRLF) sequence into a widget setting used to build email headers. The server‑side code does not validate or sanitize this input, so the CRLF sequence can survive into an outgoing email. When the password‑reset notification email is sent to a site administrator, the attacker can add a Bcc header, receive a copy of the reset link, and use it to reset the administrator password, resulting in full takeover of the administrative account.
Affected Systems
WordPress sites running wpdevteam's Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin version 6.6.10 or any older release are impacted. All builds prior to the 6.6.11 release contain the vulnerability.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity, but the EPSS score of <1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not catalogued in CISA KEV, suggesting no large‑scale attacks are currently known. Exploitation requires the attacker to be logged in with Contributor‑level or higher, limiting the threat to users already granted elevated roles. An attacker modifies the widget setting to insert a CRLF, thereby causing the injected Bcc header to be included in the administrator’s reset email. Capturing the reset link then permits the attacker to reset the administrator password and gain full site control.
OpenCVE Enrichment