CVE-2020-13126
9.9
CRITICAL · CVSS 3.1 · EPSS 8.6% (pctl 95)
In your normal cycle
Critical by CVSS (9.9), but no sign of active exploitation.
Description
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
Scoring
| CVSS | 9.9 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 8.57% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-05-17 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| elementor | elementor page builder |
References
- https://wpvulndb.com/vulnerabilities/10214
- https://www.wordfence.com/blog/2020/05/combined-attack-on-elementor-pro-and-ultimate-addons-for-elementor-puts-1-million-sites-at-risk/
- https://wpvulndb.com/vulnerabilities/10214
- https://www.wordfence.com/blog/2020/05/combined-attack-on-elementor-pro-and-ultimate-addons-for-elementor-puts-1-million-sites-at-risk/
→ the Explorer · watch your stack · NVD