CVE-2020-13125
58Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 7.2epss 2.3%
from disclosure to weapon
Published on NVDMay 17
VulnCheckMay 17
exploitation probability
2.3%top 18% of all CVEs
observed exploitation
yesVulnCheck
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
CVSS:3.0/AC:L/AV:N/A:N/C:L/I:L/PR:N/S:C/UI:N
Affected products
n/a · n/a