CVE-2020-7055
9.9
CRITICAL · CVSS 3.1 · EPSS 3.1% (pctl 87)
In your normal cycle
Critical by CVSS (9.9), but no sign of active exploitation.
Description
An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP archive.
Scoring
| CVSS | 9.9 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 3.07% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-04-22 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| elementor | elementor page builder |
References
→ the Explorer · watch your stack · NVD