CVE-2020-13125 is a vulnerability in the "Ultimate Addons for Elementor" plugin for WordPress, affecting versions prior to 1.24.2. This flaw allows unauthenticated attackers to create new user accounts with the Subscriber role, even when user registration is explicitly disabled on the WordPress site. Rated with a CVSS score of 6.5 (Medium), this vulnerability has a low attack complexity and requires no user interaction, making it easily exploitable over the network. The potential impact involves unauthorized user creation, which could lead to further compromise or spam. While not listed in the CISA KEV catalog, this vulnerability was exploited in the wild in May 2020 in conjunction with another CVE. There are Nuclei templates available for detection, but no Metasploit modules or ExploitDB entries. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.24.2CPE matchmatch criteria | cpe:2.3:a:brainstormforce:ultimate_addons_for_elementor:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.