PT-2026-36590 · WordPress · Royal Elementor Addons
Dmitry Ignatyev
·
Published
2026-05-02
·
Updated
2026-05-05
·
CVE-2026-6229
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Royal Elementor Addons versions prior to 1.7.1058
Description
The Royal Elementor Addons plugin for WordPress contains a Server-Side Request Forgery (SSRF) issue. This occurs because the
render csv data() function does not sufficiently validate user-supplied URLs, which can be bypassed by including 'docs.google.com/spreadsheets' in a query parameter. These URLs are then used in fopen() calls without blocking internal or private network addresses. Authenticated attackers with Contributor-level access or higher can exploit this to make requests to arbitrary URLs and retrieve sensitive information from internal services.Recommendations
Update the plugin to a version later than 1.7.1057.
As a temporary workaround, restrict access to the
render csv data() function to minimize the risk of exploitation.Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Royal Elementor Addons