Junglewise Threat Intelligence

CVE-2026-1641: Wow Elements Addons for Elementor server-side request forgery

CVE-2026-1641 · Severity: medium · CVSS 6.5 · Published 2026-09-19

Executive brief

The Wow Elements Addons for Elementor plugin for WordPress contains a flaw that allows authenticated site contributors and administrators to send web requests from the server to arbitrary locations. An attacker could exploit this to access internal services, retrieve sensitive data, or modify information behind the server's firewall that would otherwise be unreachable.

Technical details

The plugin passes unsanitized user input from the 'Changelog File' setting directly to the wp_remote_get function, enabling server-side request forgery (SSRF). The vulnerability requires Contributor-level or higher privileges and affects all versions up to 1.11.2. An authenticated attacker can make arbitrary web requests originating from the server to internal or external systems.

Affected products

  • Wow Elements Addons for Elementor up to and including 1.11.2

Timeline

  • 2026-09-19: disclosed

References