What is CVE-2026-0673?
The Element Pack Addons for Elementor plugin for WordPress, up to version 8.3.15, is vulnerable to Email Header Injection via the `element_pack_contact_form` AJAX action. This occurs due to insufficient sanitization of newline characters in user-supplied input. Website owners should update the plugin to the latest version immediately.
Azərbaycanca: Element Pack Addons for Elementor plaginin 8.3.15 versiyasına qədər olan bütün versiyalarında Email Header Injection zəifliyi aşkar edilib. Bu, `element_pack_contact_form` AJAX əməliyyatında istifadəçi tərəfindən daxil edilən məlumatlardakı yeni sətir simvollarının kifayət qədər təmizlənməməsi səbəbindən baş verir. WordPress sayt sahibləri plagini dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
What versions of the Element Pack Addons plugin are affected by the Email Header Injection vulnerability?
The vulnerability affects all versions of the plugin up to version 8.3.15.
Through which operation in the plugin can this vulnerability be exploited?
The vulnerability occurs via the `element_pack_contact_form` AJAX action due to insufficient sanitization of newline characters in user-supplied input.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.