Ultimate Addons for Elementor <= 1.24.1 - Registration Bypass

2020-05-06 00:00
Anonymous

Strategic Overview

Status
Patched in 1.24.2
Affected Version< 1.24.2
CVSS7.2High
CVECVE-2020-13125
View all Ultimate Addons for Elementor vulnerabilities

Vulnerability Overview

An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.

Technical Analysis

REMEDIATION: Update to version 1.24.2, or a newer patched version --- IDENTIFIER: CWE-286 (Incorrect User Management) The product does not properly manage a user within its environment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C