Executive brief
The Wow Elements Addons for Elementor plugin for WordPress contains a flaw that allows authenticated site contributors and administrators to send web requests from the server to arbitrary locations. An attacker could exploit this to access internal services, retrieve sensitive data, or modify information behind the server's firewall that would otherwise be unreachable.
Technical details
The plugin passes unsanitized user input from the 'Changelog File' setting directly to the wp_remote_get function, enabling server-side request forgery (SSRF). The vulnerability requires Contributor-level or higher privileges and affects all versions up to 1.11.2. An authenticated attacker can make arbitrary web requests originating from the server to internal or external systems.
Affected products
- Wow Elements Addons for Elementor up to and including 1.11.2
Timeline
- 2026-09-19: disclosed