๐Ÿ” CVE Alert

CVE-2026-13407

MEDIUM 6.1

Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in Form Notification Emails

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on form submission.

Vendor unknown
Product royal addons for elementor
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for unknown royal addons for elementor

Be the first to know when new medium vulnerabilities affecting unknown royal addons for elementor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / Royal Addons for Elementor
0 < 1.7.1067

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/b6bb29de-7d61-4a83-9ee1-0915ad2bda34/

Credits

Brian Willows WPScan