CVE-2020-13125: High severity brainstorm force ultimate addons for elementor vulnerability
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13125?
CVE-2020-13125 is a vulnerability in the Ultimate Addons for Elementor plugin for WordPress that allows unauthenticated attackers to create users with the Subscriber role.
What is the severity of CVE-2020-13125?
CVE-2020-13125 has a severity rating of high (6.5).
How can I fix CVE-2020-13125?
To fix CVE-2020-13125, update your Ultimate Addons for Elementor plugin to version 1.24.2 or later.
What is the affected software of CVE-2020-13125?
The affected software of CVE-2020-13125 is the Ultimate Addons for Elementor plugin before version 1.24.2 for WordPress.
Are there any references for CVE-2020-13125?
Yes, you can find references for CVE-2020-13125 at the following links: [1] https://wpvulndb.com/vulnerabilities/10214 [2] https://www.wordfence.com/blog/2020/05/combined-attack-on-elementor-pro-and-ultimate-addons-for-elementor-puts-1-million-sites-at-risk/