Description
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct outgoing email headers — the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link, and achieve full administrator account takeover.
Published: 2026-07-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Essential Addons for Elementor Templates & Widgets plugin for WordPress contains a flaw that lets an authenticated user with Contributor or higher privileges inject a carriage‑return line feed (CRLF) sequence into a widget setting used to build email headers. The server‑side code does not validate or sanitize this input, so the CRLF sequence can survive into an outgoing email. When the password‑reset notification email is sent to a site administrator, the attacker can add a Bcc header, receive a copy of the reset link, and use it to reset the administrator password, resulting in full takeover of the administrative account.

Affected Systems

WordPress sites running wpdevteam's Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin version 6.6.10 or any older release are impacted. All builds prior to the 6.6.11 release contain the vulnerability.

Risk and Exploitability

The CVSS score of 8.8 classifies the issue as high severity, but the EPSS score of <1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not catalogued in CISA KEV, suggesting no large‑scale attacks are currently known. Exploitation requires the attacker to be logged in with Contributor‑level or higher, limiting the threat to users already granted elevated roles. An attacker modifies the widget setting to insert a CRLF, thereby causing the injected Bcc header to be included in the administrator’s reset email. Capturing the reset link then permits the attacker to reset the administrator password and gain full site control.

Generated by OpenCVE AI on July 29, 2026 at 09:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Essential Addons for Elementor to version 6.6.11 or later.
  • Sanitize or remove any CRLF (carriage‑return/line‑feed) characters from email headers.
  • Restrict users with Contributor‑level or higher from editing the login/register widget setting, or disable the widget if it is not required.

Generated by OpenCVE AI on July 29, 2026 at 09:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 11 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdevteam
Wpdevteam essential Addons For Elementor – Popular Elementor Templates & Widgets
Vendors & Products Wordpress
Wordpress wordpress
Wpdevteam
Wpdevteam essential Addons For Elementor – Popular Elementor Templates & Widgets

Sat, 11 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct outgoing email headers — the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link, and achieve full administrator account takeover.
Title Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
Wpdevteam Essential Addons For Elementor – Popular Elementor Templates & Widgets
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-15T13:46:28.209Z

Reserved: 2026-07-08T19:50:24.698Z

Link: CVE-2026-15155

cve-icon Vulnrichment

Updated: 2026-07-15T13:46:24.473Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:15:05Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password