CVE-2026-17123Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-controlled URL into the wpr_webhook_url_{widget_id} option on every render (including a Contributor previewing their own draft), and the wpr_form_builder_webhook AJAX handler — registered for both authenticated and unauthenticated callers — reads that option and dispatches the outbound request via the non-safe wp_remote_post(), with no host allowlist, no scheme restriction, and no private/loopback IP filter (the plugin's existing wpr_is_blocked_remote_host / wpr_is_private_or_local_ip helpers are not called on this path). This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-16); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-16: 1Mentions · 2026-08-17: 1Technical Details · 2026-08-16: 108-1608-17
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-161
Disclosure1
2026-08-171
General1
Full discourse2 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en complementos de WordPress ❗ CVE-2026-18432 ❗ CVE-2026-17123 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-wordpress-3/ https://t.co/pIgh5axTZu

    Post summary

    The text announces two WordPress plugin vulnerabilities (CVE‑2026‑18432 and CVE‑2026‑17123) and provides links for further information, but offers no additional details or actionable content.

    00000212
    6.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-17123 Server-Side Request Forgery in Royal Elementor Addons Plugin Up To 1.7.1064 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-17123

    Post summary

    A Server‑Side Request Forgery vulnerability (CVE‑2026‑17123) has been disclosed affecting Royal Elementor Addons plugin versions up to 1.7.1064.

    00000138
    4.1K followersView on X

Explore more