CVE-2020-26596
Elementor Pro <= 3.0.5 - Authenticated Remote Code Execution in Dynamic OOO Widget
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because only the Editor role is needed to upload executable PHP code via the PHP Raw snippet. NOTE: this issue can be mitigated by removing the Dynamic OOO widget or by restricting availability of the Editor role.
El widget Dynamic OOO para el plugin Elementor Pro versiones hasta 3.0.5 para WordPress, permite a usuarios autenticados remotos ejecutar código arbitrario porque solo se necesita el rol Editor para cargar código PHP ejecutable por medio del fragmento PHP Raw. NOTA: este problema se puede mitigar eliminando el widget Dynamic OOO o restringiendo la disponibilidad del rol Editor
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-06 CVE Reserved
- 2020-10-06 CVE Published
- 2024-07-27 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://ww2.compunet.cl/dia-cero-en-plugin-de-wordpres-detectada-compunet-redteam | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://elementor.com/pro/changelog | 2021-07-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Elementor Search vendor "Elementor" | Elementor Pro Search vendor "Elementor" for product "Elementor Pro" | <= 3.0.5 Search vendor "Elementor" for product "Elementor Pro" and version " <= 3.0.5" | wordpress |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | <= 5.5.1 Search vendor "Wordpress" for product "Wordpress" and version " <= 5.5.1" | - |
Safe
|