VulnerabilityModified
CVE-2020-13125
Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
MEDIUM 6.5EPSS 2.31%
Does this matter?
Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- brainstormforce/ultimate addons for elementor
- Source
- cve@mitre.org
References
- https://wpvulndb.com/vulnerabilities/10214Not Applicable
- https://www.wordfence.com/blog/2020/05/combined-attack-on-elementor-pro-and-ultimate-addons-for-elementor-puts-1-million-sites-at-risk/Third Party Advisory
- https://wpvulndb.com/vulnerabilities/10214Not Applicable
- https://www.wordfence.com/blog/2020/05/combined-attack-on-elementor-pro-and-ultimate-addons-for-elementor-puts-1-million-sites-at-risk/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.