Executive brief
A vulnerability exists in the CRT Addons for Elementor plugin, which is used to extend the capabilities of the Elementor website builder for WordPress. An unauthorized attacker can submit malicious code through a contact form that is then stored on the website's database. When a site administrator later views these form submissions in the dashboard, the malicious code executes, potentially allowing the attacker to hijack the administrator's session, steal sensitive data, or take full control of the website.
Technical details
The CRT Addons for Elementor (also known as Free Theme Builder for Elementor) plugin fails to sanitize user-supplied input in contact form fields before storing it in the database and subsequently displaying it in the WordPress administrative dashboard. This leads to a Stored Cross-Site Scripting (XSS) vulnerability. An unauthenticated remote attacker can submit a contact form containing a malicious JavaScript payload. The attack is triggered when a logged-in administrator accesses the form submission management page, allowing the script to execute within the context of the administrator's browser session. This can lead to session hijacking, unauthorized administrative actions, or site takeover. The issue is resolved in version 1.6.7.
Affected products
- Unknown CRT Addons for Elementor (Free Theme Builder for Elementor) < 1.6.7
Timeline
- 2026-06-30: disclosed: Publicly published by WPScan
- 2026-07-21: advisory: CVE published to NVD dataset
- 2026-06-30: patched: Fixed version 1.6.7 released