🔙 목록으로 돌아가기

CVE-2020-13125: Ultimate Addons for Elementor <= 1.24.1 - Registration Bypass

TitleUltimate Addons for Elementor <= 1.24.1 - Registration Bypass
Authordaffainfo
SeverityHigh
ImpactUnauthenticated attackers can create user accounts with Subscriber role, potentially leading to further malicious activities or privilege escalation
RemediationUpdate to version 1.24.2 or later.
CVSS Score7.2
EPSS Score0.21581
CVE IDCVE-2020-13125
CWE IDNVD-CWE-noinfo
Tags cve2020 cve wp wordpress wp-plugin brainstormforce ultimate-addons-for-elementor vkev

🔍 Vulnerability Description

An issue was discovered in the “Ultimate Addons for Elementor” plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.

🌐 HTTP Request

GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:109.0) Gecko/20100101 Firefox/114.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-13125.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-13125.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A