CVE-2020-13126

An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.


We have discovered 19,317 live websites that are affected by CVE-2020-13126.

Run a Free Instant Scan




Affected Software

Product  Elementor Pro
Category Landing Page Builders
Vulnerable Domains19,317 live websites (1.51% of Elementor Pro install base)
Vulnerable Versions
  • from 0 through 2.9.4
Vulnerable Versions Count84 versions ( 33% of all versions)



Details

  • Published - May 17, 2020
  • Updated - Aug 4, 2024

Website Distribution by Country

Number of websites using CVE-2020-13126
United States3,909 websites



Germany1,527 websites
Russia1,382 websites
Israel985 websites
France867 websites
Italy766 websites
Brazil704 websites
GB702 websites
Poland671 websites
Spain648 websites

Website Distribution by TLD

Number of websites using CVE-2020-13126
.com6,670 websites
.ru1,098 websites
.de791 websites
.com.br686 websites
.it537 websites
.dk514 websites
.org504 websites
.pl503 websites
.co.uk403 websites
.com.au379 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-13126

Top websites that are affected by CVE-2020-13126. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.info Israel**,***
********.**.il Israel**,***
******.org United States**,***
*******.com Singapore**,***
********.me Switzerland**,***
******************.org GB**,***
********.com United States***,***
*******.com United States***,***
*******.********.com Bulgaria***,***
*********.com United States***,***
See full domain list

FAQ

A total of 19,317 websites have been identified as vulnerable to CVE-2020-13126, based on global website indexing conducted by WebTechSurvey.
The Elementor Pro is affected by the CVE-2020-13126 vulnerability.
Elementor Pro versions up to and including 2.9.4 are vulnerable to CVE-2020-13126.