Server-Side Request Forgery in Royal Elementor Addons Plugin for WordPress
CVE-2026-6229
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 May 2026
What is CVE-2026-6229?
The Royal Elementor Addons plugin for WordPress is susceptible to Server-Side Request Forgery due to inadequate validation of user-supplied URLs in the render_csv_data() function. By employing malicious query parameters that include 'docs.google.com/spreadsheets', authenticated users with Contributor-level access or higher can bypass defenses. This flaw permits attackers to send requests to arbitrary URLs, potentially exposing sensitive data from internal services, as these URLs are executed without restrictions on accessing private network addresses.
Affected Version(s)
Royal Addons for Elementor β Addons and Templates Kit for Elementor 0 <= 1.7.1057