← Vulnerability feed

Vulnerability record · CVE-2022-1329 · published 19 April 2022

CVE-2022-1329: Elementor Website Builder missing authorization enables file upload RCE

Elementor · Website Builder

The Elementor Website Builder plugin for WordPress versions 3.6.0 to 3.6.2 lacks a capability check in the onboarding module, allowing several AJAX actions to be executed without proper authorization. An attacker can modify site data and upload malicious files, which can lead to remote code execution.

8.8 CVSS 3.1 High EPSS 93% · top 0.2% CWE-434 · Unrestricted file uploadCWE-862 · Missing authorization
8.8CVSS 3.1 base score, v2 6.5
93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.8 and very high EPSS with public exploit references make this a high-priority remote code execution risk despite not being in KEV.

What it is

The Elementor Website Builder plugin for WordPress versions 3.6.0 to 3.6.2 lacks a capability check in the onboarding module, allowing several AJAX actions to be executed without proper authorization. An attacker can modify site data and upload malicious files, which can lead to remote code execution.

Impact

An attacker gains the ability to alter site content and upload executable files, ultimately achieving remote code execution on the affected WordPress site.

Attack surface

The flaw is reachable over the network through AJAX actions in the plugin's onboarding module. The CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N), so an authenticated low-privileged user can trigger it.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.92658, 99.8th percentile) and multiple references are tagged Exploit, indicating public exploit code exists.

What to do

  • Update Elementor Website Builder to version 3.6.3 or later, which contains the patch referenced in the vendor changeset.
  • If immediate patching is not possible, disable or restrict access to the plugin's onboarding AJAX actions.
  • Audit WordPress user roles and remove unnecessary low-privileged accounts that could reach the vulnerable AJAX endpoints.
  • Monitor file uploads and site data changes for unexpected modifications.
  • Apply the principle of least privilege to all WordPress users.

Detection

  • Review web server and WordPress logs for POST requests to admin-ajax.php with actions related to the Elementor onboarding module.
  • Monitor for newly uploaded files in wp-content/uploads and other writable directories, especially PHP files.
  • Check for unexpected changes to site options or content that could indicate unauthorized AJAX action execution.
  • Use file integrity monitoring to detect unauthorized file modifications or additions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-1329 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-47504Elementor website builder improper authentication vulnerabilityImproper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This iss…EPSS 1.5%9.8CVE-2020-7109Elementor website builder vulnerabilityThe Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.EPSS 1.7%8.8CVE-2023-48777Elementor website builder unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder…EPSS 4.1%8.1CVE-2024-24934Elementor website builder path traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulati…EPSS 0.72%7.2CVE-2023-0329Elementor website builder vulnerabilityThe Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module befo…EPSS 20%6.5CVE-2024-8494Elementor website builder information exposure vulnerabilityThe Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.25.10 …EPSS 0.31%6.5CVE-2020-20634Elementor website builder vulnerabilityElementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all securit…EPSS 0.99%6.1CVE-2022-4953Elementor website builder vulnerabilityThe Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be us…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2022-1329), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.