Medium severity5.3NVD Advisory· Published Aug 6, 2026· Updated Aug 6, 2026
CVE-2026-0673
CVE-2026-0673
Description
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the element_pack_contact_form AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email headers. This makes it possible for unauthenticated attackers to inject arbitrary email headers into emails sent by the contact form.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=8.3.15
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.