Medium severity6.5NVD Advisory· Published May 17, 2020· Updated Jun 17, 2026
CVE-2020-13125
CVE-2020-13125
Description
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
Affected products
3- cpe:2.3:a:brainstormforce:ultimate_addons_for_elementor:*:*:*:*:*:wordpress:*:*Range: <1.24.2
- WordPress/Ultimate Addons for Elementordescription
- Range: <1.24.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.