Record summary

CVE-2020-13125 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 17, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHUltimate Addons for Elementor <= 1.24.1 - Registration BypassCVSS 7.2

An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.

Impact

Unauthenticated attackers can create user accounts with Subscriber role, potentially leading to further malicious activities or privilege escalation

Remediation

Update to version 1.24.2 or later.

Authorsdaffainfo
Template tagscve2020cvewpwordpresswp-pluginbrainstormforceultimate-addons-for-elementorvkev
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:brainstormforce:ultimate_addons_for_elementor:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3