Description
The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setting directly to the wp_remote_get function without adequate validation or sanitization of the URL. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Published: 2026-09-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The Wow Elements Addons for Elementor plugin allows a Server‑Side Request Forgery flaw, classified as CWE-918. Attackers who are authenticated at the Contributor level or higher can place a crafted value in the "Changelog File" setting. The plugin passes that value directly to the WordPress wp_remote_get function without sanitization, enabling the application to issue HTTP requests to arbitrary destinations. An attacker could therefore probe or modify internal web services and potentially exfiltrate sensitive information or disrupt internal resources.

Affected Systems

Vendors and product affected are Wow Elements’ Wow Elements Addons for Elementor plugin for WordPress. All releases up to and including 1.11.2 are vulnerable; no specific patch version is listed in the data, but the problem is present in all prior releases.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not currently listed in CISA’s KEV catalog. Attacks require authentication with Contributor or higher privileges, which narrows the threat to users who can access the plugin’s settings page. The likely attack vector is via the plugin’s admin interface where the "Changelog File" field is edited; once set, the application automatically performs the outbound request during normal operation. Because the flaw facilitates arbitrary HTTP calls, it poses a risk to internal services that might be exposed only from the web server’s network.

Generated by OpenCVE AI on September 19, 2026 at 23:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Wow Elements Addons for Elementor plugin to the latest available version to remove the vulnerable code.
  • If an upgrade is not immediately available, disable plugin functionality that exposes the "Changelog File" setting—either by removing the setting via the database or by editing the plugin files to block the wp_remote_get call.
  • Restrict Contributor users from editing plugin settings or remove the Contributor role from users who do not need it to reduce the window of opportunity for exploitation.

Generated by OpenCVE AI on September 19, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions wow Elements Addons For Elementor
Wowelements
Wowelements wow Elements Addons For Elementor
Vendors & Products Wordpress-extensions
Wordpress-extensions wow Elements Addons For Elementor
Wowelements
Wowelements wow Elements Addons For Elementor

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setting directly to the wp_remote_get function without adequate validation or sanitization of the URL. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Title Wow Elements Addons for Elementor <= 1.11.2 - Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Wordpress-extensions Wow Elements Addons For Elementor
Wowelements Wow Elements Addons For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:22.660Z

Reserved: 2026-01-29T18:17:44.069Z

Link: CVE-2026-1641

cve-icon Vulnrichment

Updated: 2026-09-19T13:52:19.509Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:53.330

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-1641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)