nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-13126 CVE-2020-13126
CRITICAL
elementor elementor_page_builder Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2020-13126 has a selected CVSS score of 9.9 (critical).
Description
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 17, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
elementor_page_builderBrowse elementor / elementor_page_builder | VulnCheck | Version data not supplied | |
References
3wpvulndb.com
https://wpvulndb.com/vulnerabilities/10214 wordfence.com
https://www.wordfence.com/blog/2020/05/combined-attack-on-elementor-pro-and-ultimate-addons-for-elementor-puts-1-million-sites-at-risk