An issue exists in the "Ultimate Addons for Elementor" plugin prior to 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
brainstormforce ultimate addons for elementor |