What is CVE-2026-17565?
This vulnerability exists in the 'Animation Addons for Elementor' WordPress plugin before version 2.7.2. The lack of validation on a user-supplied value when building the host for a server-side HTTP request leads to an SSRF attack, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses. Updating to the latest plugin version is required.
Azərbaycanca: Bu zəiflik 'Animation Addons for Elementor' WordPress pluginin 2.7.2-dən əvvəlki versiyalarında aşkar edilib. Serverside HTTP sorğusu yaradarkən istifadəçi tərəfindən daxil edilən host dəyərinin doğrulanmaması SSRF hücumuna səbəb olur; identifikasiya olunmamış istifadəçilər daxili şəbəkə qovşaqlarına sorğu göndərərək məlumatları oxuya bilərlər. Pluginin ən son versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
In which version of the Animation Addons for Elementor plugin is the SSRF vulnerability fixed?
The vulnerability exists in all versions before 2.7.2, so updating to at least version 2.7.2 or the latest release is required.
Is authentication required to exploit this SSRF vulnerability?
No, the vulnerability can be exploited by unauthenticated users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.