An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.
We have discovered 19,317 live websites that are affected by CVE-2020-13126.
| Product | |
| Category | Landing Page Builders |
| Vulnerable Domains | 19,317 live websites (1.51% of Elementor Pro install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 84 versions ( 33% of all versions) |
| 3,909 websites | |
| 1,527 websites | |
| 1,382 websites | |
| 985 websites | |
| 867 websites | |
| 766 websites | |
| 704 websites | |
| 702 websites | |
| 671 websites | |
| 648 websites |
| .com | 6,670 websites |
| .ru | 1,098 websites |
| .de | 791 websites |
| .com.br | 686 websites |
| .it | 537 websites |
| .dk | 514 websites |
| .org | 504 websites |
| .pl | 503 websites |
| .co.uk | 403 websites |
| .com.au | 379 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **************.info | **,*** | ||
| ********.**.il | **,*** | ||
| ******.org | **,*** | ||
| *******.com | **,*** | ||
| ********.me | **,*** | ||
| ******************.org | **,*** | ||
| ********.com | ***,*** | ||
| *******.com | ***,*** | ||
| *******.********.com | ***,*** | ||
| *********.com | ***,*** |
FAQ