← back
CVE-2020-13125highobserved exploitation

CVE-2020-13125

58Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 7.2epss 2.3%
from disclosure to weapon
Published on NVDMay 17
VulnCheckMay 17
exploitation probability
2.3%top 18% of all CVEs
observed exploitation
yesVulnCheck
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
CVSS:3.0/AC:L/AV:N/A:N/C:L/I:L/PR:N/S:C/UI:N
Affected products
n/a · n/a