CVE · Critical

CVE-2020-13126 — Elementor Pro [elementor-pro] < 2.9.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-13126 Elementor Pro [elementor-pro] < 2.9.4 Unrestricted Upload of File with Dangerous Type Critical 9.9 < 2.9.4 2.9.4 2020-05-06

CVE-2020-13126

Elementor Pro versions before 2.9.4 contain a vulnerability that permits authenticated users to upload and execute arbitrary PHP code on the affected website. Security researchers confirmed that attackers are actively exploiting this flaw, often in combination with a separate vulnerability in Ultimate Addons for Elementor that enables unauthorized subscriber account creation. The issue affects any logged-in user regardless of their privilege level, making it a significant security risk for WordPress installations running the vulnerable plugin versions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.