CVE Database /
CVE-2020-26596
CVE · High
CVE-2020-26596 — Elementor Pro [elementor-pro] < 3.0.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-26596
|
Elementor Pro [elementor-pro] < 3.0.6 |
Improper Privilege Management |
High
8.8
|
< 3.0.6
|
3.0.6 |
2020-10-06 |
—
|
CVE-2020-26596
The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.
Source:
CVE.org
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings