SB2020051703 - Incorrect permission assignment for critical resource in Ultimate Addons for Elementor



SB2020051703 - Incorrect permission assignment for critical resource in Ultimate Addons for Elementor

Published: May 17, 2020 Updated: July 17, 2020

Security Bulletin ID SB2020051703
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Incorrect permission assignment for critical resource (CVE-ID: CVE-2020-13125)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.


Remediation

Install update from vendor's website.