CVE-2026-15155

HIGH

Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-15155. PoCs published by incogbyte.

AI-analyzed exploit summary This exploit demonstrates an authenticated (Contributor+) account takeover via email header injection in Essential Addons for Elementor <= 6.6.10. The vulnerability arises from improper sanitization of the 'Lost Password Email Content Type' widget setting, allowing CRLF injection to manipulate email headers (e.g., Bcc) in password-reset emails.

Description

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in all versions up to, and including, 6.6.10 This is due to insufficient server-side validation of a Login/Register widget setting used to construct outgoing email headers — the allowed-values restriction is enforced only in the client-side editor UI and not on the server, and the applied sanitization does not strip or encode CR/LF characters, allowing CRLF sequences stored in that setting to survive into raw mail headers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject an additional Bcc header into the WordPress administrator's password-reset notification email, receive a copy of a valid administrator password-reset link, and achieve full administrator account takeover.

Exploits (1)

github WORKING POC 4 stars
by incogbyte · pythonpoc
https://github.com/incogbyte/wp-cve-exploits/tree/main/CVE-2026-15155

This exploit demonstrates an authenticated (Contributor+) account takeover via email header injection in Essential Addons for Elementor <= 6.6.10. The vulnerability arises from improper sanitization of the 'Lost Password Email Content Type' widget setting, allowing CRLF injection to manipulate email headers (e.g., Bcc) in password-reset emails.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Essential Addons for Elementor <= 6.6.10
Auth required
Prerequisites: Contributor+ access to a WordPress site with Elementor and the vulnerable plugin version · A page containing the EA Login/Register widget with the poisoned setting (attacker-created)
mistral-large-3 · analyzed Jul 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0036
EPSS Percentile 28.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-640
Status published
Products (1)
wpdevteam/Essential Addons for Elementor – Popular Elementor Templates & Widgets < 6.6.10
Published Jul 11, 2026
Tracked Since Jul 11, 2026