CVE-2026-17565 PUBLISHED

Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery

Assigner: WPScan
Reserved: 27.07.2026 Published: 19.08.2026 Updated: 19.08.2026

The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.

Product Status

Vendor Unknown
Product Animation Addons for Elementor
Versions Default: unaffected
  • affected from 0 to 2.7.2 (excl.)

Credits

  • Seongwon Lee finder
  • WPScan coordinator

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE