CVE-2020-13126: Malicious File Upload
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13126?
CVE-2020-13126 is an issue discovered in the Elementor Pro plugin for WordPress, which allows an attacker with the Subscriber role to upload arbitrary executable files and achieve remote code execution.
What is the severity of CVE-2020-13126?
The severity of CVE-2020-13126 is critical, with a severity value of 9.9.
How can an attacker exploit CVE-2020-13126?
An attacker with the Subscriber role can exploit CVE-2020-13126 by uploading arbitrary executable files to achieve remote code execution.
Which version of Elementor Pro is affected by CVE-2020-13126?
Elementor Pro versions up to and exclusive of 2.9.4 are affected by CVE-2020-13126.
How can I fix CVE-2020-13126?
To fix CVE-2020-13126, update to Elementor Pro version 2.9.4 or later.