๐Ÿ” CVE Alert

CVE-2025-26990

UNKNOWN 0.0

WordPress Royal Elementor Addons plugin <= 1.7.1006 - Server Side Request Forgery (SSRF) vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Server Side Request Forgery.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1006.

CWE CWE-918
Vendor wp royal
Product royal elementor addons
Published Apr 15, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for wp royal royal elementor addons

Be the first to know when new unknown vulnerabilities affecting wp royal royal elementor addons are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

WP Royal / Royal Elementor Addons
0 โ‰ค 1.7.1006

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/royal-elementor-addons/vulnerability/wordpress-royal-elementor-addons-plugin-1-7-1006-server-side-request-forgery-ssrf-vulnerability?_s_id=cve

Credits

Marek Mikita | Patchstack Bug Bounty Program