Elementor Vulnerabilities and Affected Products
Vulnerabilities associated with elementor_page_builder.
Products
Clear product- Elementor Website Builder11 vulnerabilities
- Website Builder7 vulnerabilities
- Elementor Pro3 vulnerabilities
- website_builder3 vulnerabilities
- Ally2 vulnerabilities
- elementor_pro2 vulnerabilities
- elementor1 vulnerability
- Elementor Website Builder (WordPress plugin)1 vulnerability
- elementor_page_builder1 vulnerability
- Hello Elementor1 vulnerability
- Image Optimizer by Elementor1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-13126CRITICAL | elementor elementor_page_builder Unrestricted Upload of File with Dangerous TypeAn issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected. CWE-434May 17, 2020 | CVSS9.9v3.1 | EPSS8.57% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |