blog.nintechnet.com
https://blog.nintechnet.com/wordpress-elementor-plugin-fixed-safe-mode-privilege-escalation-vulnerability CVE-2020-20634
MEDIUM
Elementor 2.9.5 and below WordPress plugin Vulnerability
Record summary
CVE-2020-20634 has a selected CVSS score of 6.5 (medium).
Description
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 31, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Website BuilderBrowse elementor / Website Builder | VulnCheck | Version data not supplied | |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-20634