An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-05-17T00:38:37

Updated: 2024-08-04T12:11:19.166Z

Reserved: 2020-05-17T00:00:00

Link: CVE-2020-13126

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-05-17T01:15:11.447

Modified: 2020-08-25T12:36:12.397

Link: CVE-2020-13126

cve-icon Redhat

No data.