CVE-2026-13407
Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in Form Notification Emails
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on form submission.
| Vendor | unknown |
| Product | royal addons for elementor |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown royal addons for elementor
Be the first to know when new medium vulnerabilities affecting unknown royal addons for elementor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / Royal Addons for Elementor
0 < 1.7.1067
References
Credits
Brian Willows WPScan