CVE-2022-1329

HIGH EXPLOITED NUCLEI LAB

Elementor Website Builder < 3.6.2 - Missing Authorization

Title source: rule

Description

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

Exploits (7)

nomisec WORKING POC 22 stars
by AkuCyberSec · poc
https://github.com/AkuCyberSec/CVE-2022-1329-WordPress-Elementor-3.6.0-3.6.1-3.6.2-Remote-Code-Execution-Exploit
nomisec WORKING POC 16 stars
by mcdulltii · poc
https://github.com/mcdulltii/CVE-2022-1329
nomisec WORKING POC 4 stars
by Grazee · poc
https://github.com/Grazee/CVE-2022-1329-WordPress-Elementor-RCE
nomisec WRITEUP
by AgustinESI · poc
https://github.com/AgustinESI/CVE-2022-1329
nomisec WORKING POC
by phanthibichtram12 · remote-auth
https://github.com/phanthibichtram12/CVE-2022-1329
nomisec WRITEUP
by dexit · poc
https://github.com/dexit/CVE-2022-1329
metasploit WORKING POC EXCELLENT
by Ramuel Gall, AkuCyberSec, h00die · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/wp_plugin_elementor_auth_upload_rce.rb

Nuclei Templates (1)

Elementor Website Builder - Remote Code Execution
HIGHVERIFIEDby theamanrawat

Scores

CVSS v3 8.8
EPSS 0.9336
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2022-04-13
CWE
CWE-862 CWE-434
Status published
Products (1)
elementor/website_builder 3.6.0 - 3.6.2
Published Apr 19, 2022
Tracked Since Feb 18, 2026