What is CVE-2026-17123?
This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Royal Elementor Addons plugin for WordPress (versions up to and including 1.7.1064) via the 'webhook_url' setting in the Form Builder widget. The widget's render() method persists the attacker-controlled URL into the 'wpr_webhook_url_{widget_id}' option, allowing unauthorized requests to external resources. It is strongly recommended to update the plugin to the latest patched version immediately.
Azərbaycanca: Bu CVE, WordPress üçün Royal Elementor Addons plaginində (1.7.1064 və əvvəlki versiyalar) Form Builder widget-inin 'webhook_url' parametri vasitəsilə Server-Side Request Forgery (SSRF) zəifliyini təsvir edir. Təcavüzkar idarə etdiyi URL-i render() metodu ilə verilənlər bazası seçiminə yazdıraraq serverdən kənar resurslara icazəsiz sorğular göndərə bilər. Təsirə məruz qalan sistemlərdə plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of the Royal Elementor Addons plugin are vulnerable to the CVE-2026-17123 SSRF?
This vulnerability affects plugin versions up to and including 1.7.1064.
Through which parameter of the Form Builder widget can an attacker exploit CVE-2026-17123 to send unauthorized requests?
An attacker can send unauthorized requests to external resources via the 'webhook_url' parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.