SB2020051119 - Improper Authentication in Ultimate Addons for Elementor plugin for WordPress
Published: May 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: N/A)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A remote attacker can create subscriber-level users, even if registration is disabled on a WordPress site.
Note: This vulnerability is being used in conjunction with a 0-day vulnerability in Elementor PRO (SB2020051118) and allows the Elementor Pro vulnerability to be exploited, even if the site does not have user registration enabled.
Remediation
Install update from vendor's website.