Server-Side Request Forgery in Royal Elementor Addons Plugin for WordPress
CVE-2026-17123
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2026-17123?
The Royal Elementor Addons plugin for WordPress contains a Server-Side Request Forgery vulnerability that allows authenticated attackers, including those with Contributor-level access, to send web requests to arbitrary locations. This flaw arises from the inadequate validation of the 'webhook_url' setting within the Form Builder widget. When rendering, the attacker-controlled URL is stored and later accessed through the wpr_form_builder_webhook AJAX handler without necessary host allowance, scheme restrictions, or filters for private/loopback IPs. As a result, attackers could exploit this vulnerability to query or modify data on internal services.
Affected Version(s)
Royal Addons for Elementor β Addons and Templates Kit for Elementor 0 <= 1.7.1064