PT-2020-19362 · Elementor · Elementor

Published

2020-04-22

·

Updated

2020-08-25

·

CVE-2020-7055

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elementor version 2.7.4
Description An issue was discovered in the Elementor Import Templates function, allowing an attacker to execute arbitrary file upload. This enables the execution of code via a crafted ZIP archive.
Recommendations For Elementor version 2.7.4, update to a version that fixes this issue to prevent arbitrary file upload and code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the Elementor Import Templates function until a patch is available.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7055

Affected Products

Elementor