CVE · Medium

CVE-2026-0673 — Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.3.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-0673 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.3.16 Improper Neutralization of CRLF Sequences ('CRLF Injection') Medium 5.3 < 8.3.16 8.3.16 2026-08-06

CVE-2026-0673

The Element Pack Addons for Elementor plugin on WordPress contains a security flaw affecting all versions up to and including 8.3.15, where user-submitted input is improperly sanitized when constructing email headers via the `element_pack_contact_form` AJAX action, allowing attackers to inject arbitrary header information into emails sent through the contact form without requiring authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.