CVE Database /
CVE-2026-17123
CVE · High
CVE-2026-17123 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1065
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-17123
|
Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1065 |
Server-Side Request Forgery (SSRF) |
High
8.8
|
< 1.7.1065
|
1.7.1065 |
2026-08-15 |
—
|
CVE-2026-17123
The Royal Elementor Addons plugin for WordPress has a vulnerability in its Form Builder widget that allows attackers to make unauthorized web requests to arbitrary locations. This is due to the plugin's failure to properly validate and restrict the URLs used in the webhook setting, allowing an attacker to inject a malicious URL that is then executed by the plugin's AJAX handler. As a result, an authenticated attacker with Contributor-level access can make requests to internal services, potentially allowing them to access or modify sensitive information.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings