Vendor
medium
advisory
Unauthenticated Arbitrary File Manipulation in Royal Elementor Addons
1 TTP 1 CVEA vulnerability in the Royal Elementor Addons plugin for WordPress allows an unauthenticated, remote attacker to manipulate files on the server via improper access control.
Royal Elementor Addons
1t
1c
high
advisory
CVE-2026-17123: SSRF in Royal Elementor Addons WordPress Plugin
2 TTPs 1 CVEThe Royal Elementor Addons WordPress plugin is vulnerable to Server-Side Request Forgery due to improper handling of webhook URLs within the Form Builder widget, allowing authenticated contributors to send arbitrary outbound requests from the server.
Royal Elementor Addons
2t
1c