Junglewise Threat Intelligence

CVE-2026-13407: Royal Elementor Addons HTML injection in form notifications

CVE-2026-13407 · Severity: medium · CVSS 5.4 · Published 2026-09-16

Technologies: Royal Elementor Addons.

Executive brief

The Royal Elementor Addons WordPress plugin is used to extend WordPress page builder functionality with additional form widgets. The plugin fails to properly sanitize user input submitted through its form widget, allowing attackers to inject malicious HTML code into administrator notification emails. An attacker can exploit this to deliver phishing content, malware links, or sensitive information harvesting schemes directly into the inbox of site administrators.

Technical details

This vulnerability is an unauthenticated stored HTML injection flaw in the Royal Elementor Addons plugin before version 1.7.1067. The vulnerable component is the form widget, which accepts user-submitted data and includes it in the body of administrator notification emails without proper sanitization or HTML escaping. An unauthenticated attacker can submit a form with arbitrary HTML payload, which is then stored and rendered in the administrator's email client. This does not require authentication or any special privileges. The attack achieves arbitrary HTML injection into administrator communications, enabling phishing, social engineering, or credential harvesting attacks. The issue is fixed in version 1.7.1067 or later.

Affected products

  • Royal Elementor Royal Elementor Addons before 1.7.1067

Timeline

  • 2026-09-14: disclosed
  • 2026-09-16: advisory
  • 2026-09-16: patched: Fixed in version 1.7.1067

References