CVE-2020-13125
Ultimate Addons for Elementor plugin before 1.24.2 for WordPress Unauthenticated Subscriber User Bypass
Record summary
CVE-2020-13125 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 17, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ultimate_addons_for_elementorBrowse brainstormforce / ultimate_addons_for_elementor | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHUltimate Addons for Elementor <= 1.24.1 - Registration BypassCVSS 7.2
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
Impact
Unauthenticated attackers can create user accounts with Subscriber role, potentially leading to further malicious activities or privilege escalation
Remediation
Update to version 1.24.2 or later.
Source: ProjectDiscovery