CVE · High

CVE-2026-17123 — Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1065

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-17123 Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] < 1.7.1065 Server-Side Request Forgery (SSRF) High 8.8 < 1.7.1065 1.7.1065 2026-08-15

CVE-2026-17123

The Royal Elementor Addons plugin for WordPress has a vulnerability in its Form Builder widget that allows attackers to make unauthorized web requests to arbitrary locations. This is due to the plugin's failure to properly validate and restrict the URLs used in the webhook setting, allowing an attacker to inject a malicious URL that is then executed by the plugin's AJAX handler. As a result, an authenticated attacker with Contributor-level access can make requests to internal services, potentially allowing them to access or modify sensitive information.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.