CVE-2026-17123
8.8WP Royal · Royal Addons for Elementor
The Royal Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery, allowing authenticated attackers to perform unauthorized requests from the server.
Executive summary
The Royal Addons for Elementor plugin for WordPress contains a critical Server-Side Request Forgery vulnerability that could allow an authenticated attacker to interact with internal resources.
Vulnerability
The plugin is affected by a Server-Side Request Forgery (CWE-918) vulnerability, which allows an authenticated attacker to force the server to make unauthorized requests to internal or external systems.
Business impact
Exploitation of this vulnerability can allow attackers to bypass network perimeters, scan internal infrastructure, or access sensitive services that are not exposed to the public internet. The CVSS score of 8.8 highlights the significant risk posed to the internal network security of the host environment.
Remediation
Immediate Action: Update the Royal Addons for Elementor plugin to version 1.7.1065 or later immediately.
Proactive Monitoring: Monitor outgoing network requests from the server for unexpected connections to internal IP addresses or sensitive services.
Compensating Controls: Configure egress filtering on the host server to prevent it from initiating unauthorized connections to internal network segments.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Security teams must prioritize updating the Royal Addons for Elementor plugin to version 1.7.1065. Restricting server egress traffic is a highly recommended secondary measure to minimize the risk of unauthorized internal requests.