CVE-2026-0673 - Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Injection
CVE ID :CVE-2026-0673
Published : Aug. 6, 2026, 12:27 p.m. | 58 minutes ago
Description :The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the `element_pack_contact_form` AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email headers. This makes it possible for unauthenticated attackers to inject arbitrary email headers into emails sent by the contact form.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 6, 2026, 12:27 p.m. | 58 minutes ago
Description :The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the `element_pack_contact_form` AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email headers. This makes it possible for unauthenticated attackers to inject arbitrary email headers into emails sent by the contact form.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...