{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/royal-elementor-addons--1.7.1064/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-17123"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Royal Elementor Addons (\u003c= 1.7.1064)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Royal Elementor Addons"],"content_html":"\u003cp\u003eThe Royal Elementor Addons plugin for WordPress (versions 1.7.1064 and below) contains a critical Server-Side Request Forgery (SSRF) vulnerability identified as CVE-2026-17123. The issue stems from the Form Builder widget, specifically its webhook functionality. When a user with Contributor-level access or higher previews a draft, the widget's render method saves a user-supplied URL into the 'wpr_webhook_url_{widget_id}' option. Subsequently, the AJAX handler 'wpr_form_builder_webhook' retrieves this value and executes an outbound request via 'wp_remote_post()'. Critically, this execution path fails to invoke existing internal security helpers designed to block requests to private or loopback IP addresses, nor does it enforce host allowlisting or scheme validation. This oversight enables an attacker to force the server to interact with internal network resources, potentially leading to unauthorized data access or the manipulation of internal services residing within the hosting environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers to perform SSRF attacks, enabling them to scan internal networks, interact with local services that lack external authentication, or exfiltrate sensitive configuration data from the internal infrastructure. Given the ubiquity of WordPress installations, this vulnerability poses a significant risk to organizations hosting internal or private services within the same network segment as their public web servers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Royal Elementor Addons plugin to the latest available version beyond 1.7.1064, which contains the patch for CVE-2026-17123.\u003c/li\u003e\n\u003cli\u003eAudit access logs for the 'wpr_form_builder_webhook' AJAX action to identify potentially malicious requests originating from Contributor-level user accounts.\u003c/li\u003e\n\u003cli\u003eImplement strict egress filtering at the network level on web servers to prevent unauthorized connections from the application server to internal IP segments.\u003c/li\u003e\n\u003cli\u003eReview all custom webhook integrations for similar 'wp_remote_post()' usage that bypasses standard sanitization helper functions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T06:24:58Z","date_published":"2026-08-16T06:24:58Z","id":"https://feed.craftedsignal.io/briefs/2026-08-royal-elementor-ssrf/","summary":"The Royal Elementor Addons WordPress plugin is vulnerable to Server-Side Request Forgery due to improper handling of webhook URLs within the Form Builder widget, allowing authenticated contributors to send arbitrary outbound requests from the server.","title":"CVE-2026-17123: SSRF in Royal Elementor Addons WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-royal-elementor-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Royal Elementor Addons (\u003c= 1.7.1064)","version":"https://jsonfeed.org/version/1.1"}