CVE-2025-26990: WordPress Royal Elementor Addons plugin <= 1.7.1006 - Server Side Request Forgery (SSRF) vulnerability
Published Apr 15, 2025
·Updated
Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Server Side Request Forgery.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1006.
Affected Software
3 affected components
WP Royal Royal Elementor Addons<=1.7.1006
WordPress Royal Elementor Addons<=1.7.1006
royal-elementor-addons Royal Elementor Addons Wordpress<1.7.1007
Remediation
Information
Update the WordPress Royal Elementor Addons plugin to the latest available version (at least 1.7.1007).
Event History
Apr 15, 2025
CVE Published
via MITRE·11:59 AM
Data Sourced
via MITRE·11:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26990?
CVE-2025-26990 is classified as a Server-Side Request Forgery (SSRF) vulnerability with a high risk of exploitation.
2
How do I fix CVE-2025-26990?
To fix CVE-2025-26990, update the WP Royal Royal Elementor Addons to a version above 1.7.1006.
3
What versions are affected by CVE-2025-26990?
CVE-2025-26990 affects all versions of WP Royal Royal Elementor Addons up to and including 1.7.1006.
4
What are the implications of CVE-2025-26990?
Exploitation of CVE-2025-26990 could allow an attacker to perform unauthorized requests on behalf of the server.
5
Is CVE-2025-26990 under active exploitation?
As of now, there have been reports indicating that CVE-2025-26990 is actively being targeted by attackers.