CVE-2026-15155
wpdevteam Essential Addons for Elementor – Popular Elementor Templates & Widgets
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct outgoing email headers — the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers....
- CVSS
- 8.8
- EPSS
- 0.36% 28.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11