SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-20634

Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature.

MEDIUM 6.5EPSS 0.99%

Does this matter?

Lower severity and a low EPSS score (0.99%). Track it; it rarely justifies an emergency change on its own.

Description

Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.99% probability · 61th percentile
CISA KEV
Not listed
Affected
elementor/website builder
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.