SB2020051119 - Improper Authentication in Ultimate Addons for Elementor plugin for WordPress



SB2020051119 - Improper Authentication in Ultimate Addons for Elementor plugin for WordPress

Published: May 11, 2020

Security Bulletin ID SB2020051119
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: N/A)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker can create subscriber-level users, even if registration is disabled on a WordPress site.

Note: This vulnerability is being used in conjunction with a 0-day vulnerability in Elementor PRO (SB2020051118) and allows the Elementor Pro vulnerability to be exploited, even if the site does not have user registration enabled. 


Remediation

Install update from vendor's website.