PT-2026-73098 · WordPress · Royal Elementor Addons

·

CVE-2026-17123

·

Published

2026-08-16

·

Updated

2026-08-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Royal Elementor Addons versions prior to 1.7.1065
Description An issue exists in the Form Builder widget's webhook url setting that allows Server-Side Request Forgery (SSRF), a flaw where an attacker forces a server to make requests to an unintended location. The render() method saves a user-controlled URL into the wpr webhook url {widget id} option. Subsequently, the wpr form builder webhook AJAX handler reads this option and executes an outbound request using the wp remote post() function. Because the process lacks a host allowlist, scheme restrictions, and filters for private or loopback IP addresses, authenticated attackers with Contributor-level access or higher can trigger web requests to arbitrary locations from the server to query or modify internal services.
Recommendations Update Royal Elementor Addons to a version newer than 1.7.1064. As a temporary mitigation, restrict access to the Form Builder widget's webhook url setting for users with Contributor-level permissions.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17123

Affected Products

Royal Elementor Addons