CVE-2026-1641 Overview
The Wow Elements Addons for Elementor plugin for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability in all versions up to and including 1.11.2. The flaw exists because the plugin passes user-controlled input from the Changelog File setting directly to the wp_remote_get function without adequate URL validation or sanitization. Authenticated attackers with Contributor-level access or above can issue web requests to arbitrary destinations originating from the vulnerable WordPress instance. This behavior enables attackers to query internal services, probe network topology, and potentially modify information exposed through internal HTTP endpoints. The vulnerability is tracked under CWE-918: Server-Side Request Forgery.
Critical Impact
Authenticated contributors can pivot through the WordPress server to reach internal-only services, cloud metadata endpoints, and other network resources unreachable from the public internet.
Affected Products
- Wow Elements Addons for Elementor plugin for WordPress, versions up to and including 1.11.2
- WordPress installations using the vulnerable changelog.php widget component
- Sites permitting Contributor-level or higher user registration where the plugin is active
Discovery Timeline
- 2026-09-19 - CVE-2026-1641 published to the National Vulnerability Database
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-1641
Vulnerability Analysis
The vulnerability resides in the changelog widget of the Wow Elements Addons for Elementor plugin. The widget accepts a URL through the Changelog File configuration setting and fetches its contents server-side using the WordPress HTTP API. Because the plugin does not restrict the target host, scheme, or resolved IP address, the request executes against any endpoint an authenticated Contributor supplies. The plugin author addressed the issue in version 1.5.6, based on the referenced changeset. The vulnerability is limited to authenticated attackers but requires only Contributor privileges, which are commonly granted on multi-author sites and are trivial to obtain where open registration is enabled.
Root Cause
The root cause is missing input validation on the URL passed to wp_remote_get inside the changelog widget (includes/widgets/changelog.php). The plugin trusts user-supplied strings without enforcing an allowlist of hostnames, blocking private IP ranges, or restricting the URL scheme. This design permits requests to loopback addresses, RFC 1918 networks, link-local ranges such as 169.254.169.254, and non-HTTP schemes supported by the underlying transport.
Attack Vector
An authenticated attacker with Contributor access edits or creates a page containing the vulnerable changelog widget. The attacker sets the Changelog File field to an internal URL, for example a cloud instance metadata endpoint, an internal admin panel, or a service bound to 127.0.0.1. When the widget renders, the WordPress server issues an outbound request to the specified URL and returns response data through the plugin's execution path. Because the request originates from the server, it bypasses network segmentation that would block equivalent requests from the attacker's browser.
See the Wordfence Vulnerability Report and the WordPress plugin source at line 786 of changelog.php for the affected code path.
Detection Methods for CVE-2026-1641
Indicators of Compromise
- Outbound HTTP requests from the WordPress PHP worker to internal IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or loopback addresses
- Requests from the WordPress host to cloud metadata endpoints such as 169.254.169.254 or metadata.google.internal
- Unexpected User-Agent: WordPress/* traffic reaching internal service endpoints
- Contributor-authored posts or drafts containing the Wow Elements changelog widget with unusual URL configuration
Detection Strategies
- Inspect WordPress postmeta entries for the changelog widget referencing non-public URLs or private IP addresses
- Correlate egress firewall logs with the WordPress server IP and flag requests to internal networks or metadata services
- Enable and review PHP error and access logs for repeated wp_remote_get invocations tied to the changelog widget
Monitoring Recommendations
- Alert on any HTTP request originating from web application servers to link-local address 169.254.169.254
- Monitor new Contributor account creation followed shortly by page or template edits invoking Elementor widgets
- Baseline outbound HTTP destinations from the WordPress host and alert on deviations
How to Mitigate CVE-2026-1641
Immediate Actions Required
- Update the Wow Elements Addons for Elementor plugin to a version above 1.11.2 that contains the SSRF fix
- Audit existing Contributor and Author accounts and remove those that are unused or unverified
- Restrict outbound network access from the WordPress server to only required destinations using host or network firewalls
- Block the WordPress server from reaching cloud metadata endpoints (IMDSv1) and require IMDSv2 where applicable
Patch Information
The vendor addressed the SSRF condition in the plugin changelog widget. Refer to the WordPress plugin changeset for the code-level fix and the tagged 1.5.6 release source for the patched implementation. Administrators should install the latest available plugin version through the WordPress plugin manager.
Workarounds
- Deactivate and delete the Wow Elements Addons for Elementor plugin until the site can be patched
- Remove the changelog widget from any templates or pages while retaining the plugin for other functionality
- Restrict role capabilities so that Contributors cannot edit Elementor templates containing the vulnerable widget
- Deploy a Web Application Firewall rule that blocks Elementor editor requests containing internal IP addresses in widget configuration payloads
# Example egress restriction using iptables on the WordPress host
# Block outbound requests from the web server user to private ranges and metadata IP
iptables -A OUTPUT -m owner --uid-owner www-data -d 169.254.169.254 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 10.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 172.16.0.0/12 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 192.168.0.0/16 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 127.0.0.0/8 -j REJECT
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
