CVE-2026-17565
Animation Addons for Elementor
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.
- CVSS
- 7.2
- EPSS
- 0.20% 9.89% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.19