Executive brief
The Royal Elementor Addons WordPress plugin is used to extend WordPress page builder functionality with additional form widgets. The plugin fails to properly sanitize user input submitted through its form widget, allowing attackers to inject malicious HTML code into administrator notification emails. An attacker can exploit this to deliver phishing content, malware links, or sensitive information harvesting schemes directly into the inbox of site administrators.
Technical details
This vulnerability is an unauthenticated stored HTML injection flaw in the Royal Elementor Addons plugin before version 1.7.1067. The vulnerable component is the form widget, which accepts user-submitted data and includes it in the body of administrator notification emails without proper sanitization or HTML escaping. An unauthenticated attacker can submit a form with arbitrary HTML payload, which is then stored and rendered in the administrator's email client. This does not require authentication or any special privileges. The attack achieves arbitrary HTML injection into administrator communications, enabling phishing, social engineering, or credential harvesting attacks. The issue is fixed in version 1.7.1067 or later.
Affected products
- Royal Elementor Royal Elementor Addons before 1.7.1067
Timeline
- 2026-09-14: disclosed
- 2026-09-16: advisory
- 2026-09-16: patched: Fixed in version 1.7.1067