PT-2026-78289 · WordPress · Animation Addons For Elementor
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Animation Addons for Elementor versions prior to 2.7.2
Description
Insufficient validation of user-supplied values allows unauthenticated users to manipulate the host of a server-side HTTP request. This enables the site to issue requests to internal hosts and read the responses back, a behavior known as Server-Side Request Forgery (SSRF), where an attacker induces the server to make requests to an unintended location.
Recommendations
Update Animation Addons for Elementor to version 2.7.2 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Animation Addons For Elementor