peter bassill · operator
$ cve CVE-2020-13126 JSON

CVE-2020-13126

9.9
CRITICAL · CVSS 3.1 · EPSS 8.6% (pctl 95)

In your normal cycle

Critical by CVSS (9.9), but no sign of active exploitation.

Description

An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.

Scoring

CVSS9.9 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS8.57% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploitnone known
Published2020-05-17
Last modified2026-06-17

Affected (1)

VendorProduct
elementorelementor page builder

References

→ the Explorer  ·  watch your stack  ·  NVD