A vulnerability, which was classified as critical, has been found in wproyal Royal Addons Plugin up to 1.7.1064 on WordPress. This affects the function
wp_remote_post of the component Form Builder Widget. The manipulation of the argument webhook_url leads to server-side request forgery.
This vulnerability is documented as CVE-2026-17123. The attack can be initiated remotely. There is not any exploit available.