Vulnerability Description
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-17565?
CVE-2026-17565 is a vulnerability with a CVSS score of 7.2 (HIGH). The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated user...
How severe is CVE-2026-17565?
CVE-2026-17565 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-17565?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.