CVE-2020-13126
Elementor Pro versions before 2.9.4 contain a vulnerability that permits authenticated users to upload and execute arbitrary PHP code on the affected website. Security researchers confirmed that attackers are actively exploiting this flaw, often in combination with a separate vulnerability in Ultimate Addons for Elementor that enables unauthorized subscriber account creation. The issue affects any logged-in user regardless of their privilege level, making it a significant security risk for WordPress installations running the vulnerable plugin versions.
Based on public CVE data (MITRE/NVD).