CVE-2026-17565: Unknown Animation Addons For Elementor

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.

Affected products

  • Unknown Animation Addons For Elementor: before 2.7.2 (fixed in 2.7.2)

Published 2026-08-19. Last modified 2026-08-26.