Impact
The Wow Elements Addons for Elementor plugin allows a Server‑Side Request Forgery flaw, classified as CWE-918. Attackers who are authenticated at the Contributor level or higher can place a crafted value in the "Changelog File" setting. The plugin passes that value directly to the WordPress wp_remote_get function without sanitization, enabling the application to issue HTTP requests to arbitrary destinations. An attacker could therefore probe or modify internal web services and potentially exfiltrate sensitive information or disrupt internal resources.
Affected Systems
Vendors and product affected are Wow Elements’ Wow Elements Addons for Elementor plugin for WordPress. All releases up to and including 1.11.2 are vulnerable; no specific patch version is listed in the data, but the problem is present in all prior releases.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not currently listed in CISA’s KEV catalog. Attacks require authentication with Contributor or higher privileges, which narrows the threat to users who can access the plugin’s settings page. The likely attack vector is via the plugin’s admin interface where the "Changelog File" field is edited; once set, the application automatically performs the outbound request during normal operation. Because the flaw facilitates arbitrary HTTP calls, it poses a risk to internal services that might be exposed only from the web server’s network.
OpenCVE Enrichment