CVE-2026-13407
Received Received - Intake

Unauthenticated HTML Email Injection in Royal Elementor Addons

Vulnerability report for CVE-2026-13407, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: WPScan

Description

The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on form submission.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
royal_elementor_addons royal_elementor_addons to 1.7.1067 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored HTML injection in the Royal Elementor Addons WordPress plugin before version 1.7.1067. It occurs because the plugin does not properly sanitize or escape user-submitted form widget values before including them in administrator notification emails. This allows unauthenticated attackers to inject arbitrary HTML code into these emails when a form is submitted.

Detection Guidance

Check the installed version of the Royal Elementor Addons plugin. If it is below 1.7.1067, the system is vulnerable. Inspect email templates or notification settings for unexpected HTML content in administrator emails.

Impact Analysis

An attacker could exploit this to send malicious HTML content to the site administrator via email. This could lead to phishing attacks, session hijacking, or defacement if the injected HTML includes malicious scripts or links. The impact is limited to email content and does not directly compromise the server.

Compliance Impact

This vulnerability could potentially affect compliance by exposing administrators to phishing or malicious content via email, which may lead to unauthorized access or data breaches. However, the direct impact on GDPR or HIPAA compliance depends on whether such incidents result in data exposure or unauthorized processing.

Mitigation Strategies

Update the Royal Elementor Addons plugin to version 1.7.1067 or later immediately. Review recent administrator emails for suspicious HTML content and remove any unauthorized injections.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13407. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart