Showing 1 vulnerability on this page for elementor_page_builder

Signals CISA KEV Ransomware Nuclei
Elementor vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

elementor elementor_page_builder Unrestricted Upload of File with Dangerous Type

An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.

CWE-434May 17, 2020
CVSS9.9v3.1EPSS8.57%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX