Security Advisory

CVE-2026-17565

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-19 06:00:18
Last updated 2026-08-19 18:09:30
Assigner WPScan
CVSS score 7.2
State PUBLISHED

Description

The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.