PT-2026-73098 · WordPress · Royal Elementor Addons
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Royal Elementor Addons versions prior to 1.7.1065
Description
An issue exists in the Form Builder widget's
webhook url setting that allows Server-Side Request Forgery (SSRF), a flaw where an attacker forces a server to make requests to an unintended location. The render() method saves a user-controlled URL into the wpr webhook url {widget id} option. Subsequently, the wpr form builder webhook AJAX handler reads this option and executes an outbound request using the wp remote post() function. Because the process lacks a host allowlist, scheme restrictions, and filters for private or loopback IP addresses, authenticated attackers with Contributor-level access or higher can trigger web requests to arbitrary locations from the server to query or modify internal services.Recommendations
Update Royal Elementor Addons to a version newer than 1.7.1064.
As a temporary mitigation, restrict access to the Form Builder widget's
webhook url setting for users with Contributor-level permissions.Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Royal Elementor Addons