Vulnerability record · CVE-2022-1329 · published 19 April 2022
CVE-2022-1329: Elementor Website Builder missing authorization enables file upload RCE
Elementor · Website Builder
The Elementor Website Builder plugin for WordPress versions 3.6.0 to 3.6.2 lacks a capability check in the onboarding module, allowing several AJAX actions to be executed without proper authorization. An attacker can modify site data and upload malicious files, which can lead to remote code execution.
Description
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 and very high EPSS with public exploit references make this a high-priority remote code execution risk despite not being in KEV.
What it is
The Elementor Website Builder plugin for WordPress versions 3.6.0 to 3.6.2 lacks a capability check in the onboarding module, allowing several AJAX actions to be executed without proper authorization. An attacker can modify site data and upload malicious files, which can lead to remote code execution.
Impact
An attacker gains the ability to alter site content and upload executable files, ultimately achieving remote code execution on the affected WordPress site.
Attack surface
The flaw is reachable over the network through AJAX actions in the plugin's onboarding module. The CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N), so an authenticated low-privileged user can trigger it.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.92658, 99.8th percentile) and multiple references are tagged Exploit, indicating public exploit code exists.
What to do
- Update Elementor Website Builder to version 3.6.3 or later, which contains the patch referenced in the vendor changeset.
- If immediate patching is not possible, disable or restrict access to the plugin's onboarding AJAX actions.
- Audit WordPress user roles and remove unnecessary low-privileged accounts that could reach the vulnerable AJAX endpoints.
- Monitor file uploads and site data changes for unexpected modifications.
- Apply the principle of least privilege to all WordPress users.
Detection
- Review web server and WordPress logs for POST requests to admin-ajax.php with actions related to the Elementor onboarding module.
- Monitor for newly uploaded files in wp-content/uploads and other writable directories, especially PHP files.
- Check for unexpected changes to site options or content that could indicate unauthorized AJAX action execution.
- Use file integrity monitoring to detect unauthorized file modifications or additions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-1329 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-1329), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.