CVE-2020-7055: Malicious File Upload
Published Apr 22, 2020
·Updated
An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP archive.
Affected Software
1 affected component
Elementor Elementor Page Builder Wordpress<=2.7.4
Event History
Apr 22, 2020
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
Description
Frequently Asked Questions
1
What is CVE-2020-7055?
CVE-2020-7055 is a vulnerability discovered in Elementor 2.7.4 that allows for arbitrary file upload, leading to code execution.
2
How severe is CVE-2020-7055?
CVE-2020-7055 has a severity rating of critical with a score of 9.9.
3
Which software version is affected by CVE-2020-7055?
Elementor 2.7.4 is the affected version by CVE-2020-7055.
4
What is the CWE-ID associated with CVE-2020-7055?
The CWE-ID associated with CVE-2020-7055 is CWE-434.
5
How can I fix CVE-2020-7055?
To fix CVE-2020-7055, update Elementor to a version beyond 2.7.4.