CVE-2022-1329

HIGH EXPLOITED NUCLEI LAB

Elementor Website Builder 3.6.0-3.6.2 - Authenticated Remote Code Execution via Onboarding Module AJAX Actions

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-1329 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 7 public exploits from researchers including AkuCyberSec, mcdulltii, Grazee, including a Metasploit module exploits/multi/http/wp_plugin_elementor_auth_upload_rce. A Nuclei detection template is also available.

AI-analyzed exploit summary This is a functional exploit for CVE-2022-1329, targeting a broken access control vulnerability in WordPress Elementor versions 3.6.0-3.6.2. It allows authenticated users to upload and execute arbitrary PHP files by exploiting the `elementor_upload_and_install_pro` AJAX action.

Description

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

Exploits (7)

nomisec WORKING POC 22 stars
by AkuCyberSec · poc
https://github.com/AkuCyberSec/CVE-2022-1329-WordPress-Elementor-3.6.0-3.6.1-3.6.2-Remote-Code-Execution-Exploit

This is a functional exploit for CVE-2022-1329, targeting a broken access control vulnerability in WordPress Elementor versions 3.6.0-3.6.2. It allows authenticated users to upload and execute arbitrary PHP files by exploiting the `elementor_upload_and_install_pro` AJAX action.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Elementor Plugin 3.6.0, 3.6.1, 3.6.2
Auth required
Prerequisites: Valid WordPress credentials · Access to /wp-admin · A crafted ZIP file containing a malicious PHP payload
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 16 stars
by mcdulltii · poc
https://github.com/mcdulltii/CVE-2022-1329

This is a functional exploit for CVE-2022-1329, targeting a broken access control vulnerability in Elementor WordPress plugin versions 3.6.0-3.6.2. It allows authenticated users to upload and execute arbitrary PHP files via a crafted ZIP archive.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Elementor WordPress Plugin 3.6.0, 3.6.1, 3.6.2
Auth required
Prerequisites: Valid WordPress credentials · Access to /wp-admin · Ability to craft a malicious ZIP file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 4 stars
by Grazee · poc
https://github.com/Grazee/CVE-2022-1329-WordPress-Elementor-RCE

This repository contains a Python-based PoC for CVE-2022-1329, an authenticated RCE vulnerability in WordPress Elementor versions 3.6.0-3.6.2. The exploit leverages broken access control to upload and execute a malicious ZIP file containing a PHP payload via the Elementor plugin's AJAX handler.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Elementor 3.6.0, 3.6.1, 3.6.2
Auth required
Prerequisites: Valid WordPress credentials (non-admin role sufficient) · Elementor plugin version 3.6.0-3.6.2 installed · Ability to upload a ZIP file containing a malicious PHP payload
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by AgustinESI · poc
https://github.com/AgustinESI/CVE-2022-1329

This repository provides a detailed writeup and instructions for exploiting CVE-2022-1329 in WordPress 6.1.1 with Elementor 3.6.1, followed by privilege escalation using Dirty Pipe (CVE-2022-0847) on Ubuntu 20.04 with Kernel 5.9.12. It includes setup, exploitation steps, and privilege escalation guidance.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: WordPress 6.1.1 with Elementor 3.6.1
No auth needed
Prerequisites: Ubuntu 20.04 · WordPress 6.1.1 with Elementor 3.6.1 · Kernel 5.9.12 · Administrator access for kernel modification
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by phanthibichtram12 · remote-auth
https://github.com/phanthibichtram12/CVE-2022-1329

This is a functional exploit for CVE-2022-1329, targeting a vulnerability in the Elementor WordPress plugin (versions 3.6.0-3.6.2) that allows authenticated users to upload and execute arbitrary PHP files via a flawed AJAX handler. The PoC includes authentication, nonce retrieval, and payload upload steps but does not include an actual payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Elementor WordPress Plugin 3.6.0, 3.6.1, 3.6.2
Auth required
Prerequisites: Valid WordPress credentials · Elementor plugin version 3.6.0-3.6.2 · Ability to craft a malicious ZIP file with specific structure
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by dexit · poc
https://github.com/dexit/CVE-2022-1329

This repository provides a detailed writeup and references for CVE-2022-1329, a vulnerability in the Elementor Website Builder plugin for WordPress. The vulnerability allows unauthorized execution of AJAX actions due to a missing capability check, potentially leading to remote code execution.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Elementor Website Builder plugin for WordPress versions 3.6.0 to 3.6.2
No auth needed
Prerequisites: Access to the target WordPress site with the vulnerable Elementor plugin installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Ramuel Gall, AkuCyberSec, h00die · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/wp_plugin_elementor_auth_upload_rce.rb

This Metasploit module exploits an authenticated file upload vulnerability in WordPress Elementor plugin (CVE-2022-1329), allowing RCE by uploading a malicious PHP file disguised as an Elementor Pro plugin. It requires valid credentials and leverages a nonce for CSRF protection bypass.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Elementor Plugin 3.6.0 - 3.6.2
Auth required
Prerequisites: Valid WordPress credentials (Subscriber role or higher) · Elementor plugin version 3.6.0-3.6.2 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Elementor Website Builder - Remote Code Execution
HIGHVERIFIEDby theamanrawat

Scores

CVSS v3 8.8
EPSS 0.9294
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2022-04-13
CWE
CWE-862 CWE-434
Status published
Products (1)
elementor/website_builder 3.6.0 - 3.6.2
Published Apr 19, 2022
Tracked Since Feb 18, 2026