← Back to CVE List

CVE-2020-13126

Published: 2020-05-17T01:15Z
Last Modified: 2024-11-21T05:00Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt