Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-1641— Wow Elements Addons for Elementor <= 1.11.2 - Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting

Quick assessment

Affected
wowelements Wow Elements Addons for Elementor
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Wow Elements Addons for Elementor 插件在 1.11.2 及之前所有版本中均存在服务端请求伪造(SSRF)漏洞。 该漏洞产生的原因是:插件将来自“Changelog File”设置中的用户可控输入直接传递给 函数,而对 URL 未进行充分的验证或过滤。 这使得拥有 Contributor(贡献者)或更高权限的已认证攻击者能够发起源自 Web 应用的任意位置的网络请求,从而查询甚至修改内部服务中的信息。

CVSS 6.5 · Medium EPSS 0.28% · P20

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle

Affected Version Matrix 1

VendorProduct Version RangeStatus
wowelements Wow Elements Addons for Elementor ≤ 1.11.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-1641

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Wow Elements Addons for Elementor <= 1.11.2 - Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting
Source: CVE Program / CVE List V5
Vulnerability Description
The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is due to the plugin passing user-controlled input from the 'Changelog File' setting directly to the wp_remote_get function without adequate validation or sanitization of the URL. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wowelements Wow Elements Addons for Elementor 0 ~ 1.11.2 -

II. Public POCs for CVE-2026-1641

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-1641

登录查看更多情报信息。

Vendor Pages for CVE-2026-1641 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-1641

No comments yet


Leave a comment