What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in TheInnovs ElementsCSS Addons for Elementor css-for-elementor allows Server Side Request Forgery.This issue affects ElementsCSS Addons for Elementor: from n/a through <= 1.0.8.9.
Explanation of Vulnerability in Simple Terms
02Summary
ElementsCSS Addons for Elementor versions up to 1.0.8.9 contain a server-side request forgery vulnerability. An attacker can make the site send HTTP requests to internal or external systems on the attacker's behalf. The vulnerability requires specific network conditions to exploit but can leak sensitive information or interact with internal services.
What an attacker can do
03Attacker Capabilities
Make your site send HTTP requests to internal systems or external URLs to read data or interact with services.
Potential impact on your site
04Site Impact
Attackers could read internal service responses, access metadata services, or interact with backend systems your site connects to.
Conditions required to exploit
05Prerequisites
Network access to the site; specific network conditions required (high attack complexity).
Key dates
06Disclosure timeline
April 1, 2025
CVE published
May 12, 2026
Record updated