CVE · High

CVE-2026-15155 — Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15155 Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.11 Weak Password Recovery Mechanism for Forgotten Password High 8.8 < 6.6.11 6.6.11 2026-07-10

CVE-2026-15155

The Essential Addons for Elementor plugin versions up to 6.6.10 are susceptible to authenticated account takeover via email header injection. Insufficient server-side validation in the Login/Register widget setting allows attackers with Contributor-level access or higher to inject a Bcc header into password-reset emails, gaining access to administrator password-reset links and potentially taking full control of the admin account.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.