CVE-2026-17565: Unknown Animation Addons For Elementor
High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a server-side HTTP request, allowing unauthenticated users to make the site issue requests to internal hosts and read the responses back.
Affected products
- Unknown Animation Addons For Elementor: before 2.7.2 (fixed in 2.7.2)
Published 2026-08-19. Last modified 2026-08-26.