CVE-2020-13125: Brainstormforce Ultimate Addons For Elementor
Medium severity, CVSS 6.5. EPSS: 2.3% chance of exploitation in the next 30 days.
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.
Affected products
- Brainstormforce Ultimate Addons For Elementor: before 1.24.2 (fixed in 1.24.2)
Published 2020-05-17. Last modified 2026-06-17.