Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons allows Server Side Request Forgery. This issue affects Royal Elementor Addons: from n/a through 1.7.1006.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10942 | Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons allows Server Side Request Forgery. This issue affects Royal Elementor Addons: from n/a through 1.7.1006. |
Fixes
Solution
Update the WordPress Royal Elementor Addons plugin to the latest available version (at least 1.7.1007).
Workaround
No workaround given by the vendor.
References
History
Tue, 08 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Royal-elementor-addons
Royal-elementor-addons royal Elementor Addons |
|
| CPEs | cpe:2.3:a:royal-elementor-addons:royal_elementor_addons:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Royal-elementor-addons
Royal-elementor-addons royal Elementor Addons |
Tue, 15 Apr 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons allows Server Side Request Forgery. This issue affects Royal Elementor Addons: from n/a through 1.7.1006. | |
| Title | WordPress Royal Elementor Addons plugin <= 1.7.1006 - Server Side Request Forgery (SSRF) vulnerability | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-04-15T13:49:29.211Z
Reserved: 2025-02-17T11:51:57.195Z
Link: CVE-2025-26990
No data.
Status : Analyzed
Published: 2025-04-15T12:15:21.597
Modified: 2025-07-08T18:20:57.207
Link: CVE-2025-26990
No data.
OpenCVE Enrichment
No data.
EUVD