Elementor Website Builder < 3.6.2 - Missing Authorization
Title source: ruleDescription
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.
Exploits (7)
nomisec
WORKING POC
22 stars
by AkuCyberSec · poc
https://github.com/AkuCyberSec/CVE-2022-1329-WordPress-Elementor-3.6.0-3.6.1-3.6.2-Remote-Code-Execution-Exploit
nomisec
WORKING POC
4 stars
by Grazee · poc
https://github.com/Grazee/CVE-2022-1329-WordPress-Elementor-RCE
nomisec
WORKING POC
by phanthibichtram12 · remote-auth
https://github.com/phanthibichtram12/CVE-2022-1329
metasploit
WORKING POC
EXCELLENT
by Ramuel Gall, AkuCyberSec, h00die · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/wp_plugin_elementor_auth_upload_rce.rb
Nuclei Templates (1)
Elementor Website Builder - Remote Code Execution
HIGHVERIFIEDby theamanrawat
References (4)
Scores
CVSS v3
8.8
EPSS
0.9336
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Lab Environment
Details
VulnCheck KEV
2022-04-13
CWE
CWE-862
CWE-434
Status
published
Products (1)
elementor/website_builder
3.6.0 - 3.6.2
Published
Apr 19, 2022
Tracked Since
Feb 18, 2026