Описание
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.9.4 (исключая)
cpe:2.3:a:elementor:elementor_page_builder:*:*:*:*:pro:wordpress:*:*
EPSS
Процентиль: 98%
0.67023
Средний
9.9 Critical
CVSS3
9.9 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434
Связанные уязвимости
github
больше 3 лет назад
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
EPSS
Процентиль: 98%
0.67023
Средний
9.9 Critical
CVSS3
9.9 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-434