← Back to browse · API

CVE-2020-13126

Severity
CRITICAL
CVSS
9.9
EPSS
0.08565
Risk score
42.6
CISA KEV
No
PoC
No
Published
2020-05-17
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2020-5402, GHSA-Q42J-4CV4-VF65
Products
n/a:n/a n/a
Sources
euvd EUVD-2020-5402

Description

An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.

References