SB2020051703 - Incorrect permission assignment for critical resource in Ultimate Addons for Elementor
Published: May 17, 2020 Updated: July 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Incorrect permission assignment for critical resource (CVE-ID: CVE-2020-13125)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
Remediation
Install update from vendor's website.