WordPress Plugin Vulnerabilities

Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery

Description

The plugin does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.

Proof of Concept

Affects Plugins

References

Classification

Type
SSRF
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Seongwon Lee
Submitter
Seongwon Lee
Verified
Yes

Timeline

Publicly Published
2026-08-17 (about 3 days ago)
Added
2026-08-17 (about 2 days ago)
Last Updated
2026-08-19 (about 9 hours ago)

Other