CVE-2026-11767 PUBLISHED

CRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form

Assigner: WPScan
Reserved: 09.06.2026 Published: 21.07.2026 Updated: 21.07.2026

The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute when a logged-in administrator views the form submissions.

Product Status

Vendor Unknown
Product Free Theme Builder for Elementor
Versions Default: unaffected
  • affected from 0 to 1.6.7 (excl.)

Credits

  • hitarth shah finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE