PT-2020-13342 · Elementor · Ultimate Addons For Elementor

Published

2020-05-17

·

Updated

2025-12-30

·

CVE-2020-13125

CVSS v3.1

7.2

High

VectorAC:L/AV:N/A:N/C:L/I:L/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Ultimate Addons for Elementor plugin versions prior to 1.24.2
Description An issue in the Ultimate Addons for Elementor plugin allows unauthenticated attackers to create users with the Subscriber role, even when registration is disabled. This issue has been exploited in the wild.
Recommendations For Ultimate Addons for Elementor plugin versions prior to 1.24.2, update to version 1.24.2 or later to resolve the issue.

Fix

Related Identifiers

CVE-2020-13125

Affected Products

Ultimate Addons For Elementor