CVE-2026-17123: Royal Elementor Addons Plugin for WordPress Server-Side Request Forgery Vulnerability
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.7.1064. An authenticated attacker with Contributor-level access and above can exploit this vulnerability to make web requests to arbitrary locations, potentially querying and modifying information from internal services. The CVSS score for this vulnerability is 8.8, indicating a high severity level.