Wordpress Plugin Elementor Authenticated Upload Remote Code Execution

zetlyn/cve-metasploit exploit cve CVE-2022-1329 known 2022-03-29

https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/wp_plugin_elementor_auth_upload_rce.rb

Properties

platformPHP
receipt
Source
Metasploit exploit modules
Its words
PHP
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 21:42 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php",
  "author": [
    "Ramuel Gall",
    "AkuCyberSec",
    "h00die"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "The WordPress plugin Elementor versions 3.6.0 - 3.6.2, inclusive have a vulnerability\n          that allows any authenticated user to upload and execute any PHP file. This is achieved\n          by sending a request to install Elementor Pro from a user supplied zip file.\n          Any user with Subscriber or more permissions is able to execute this.\n          Tested against Elementor 3.6.1",
  "disclosure_date": "2022-03-29",
  "fullname": "exploit/multi/http/wp_plugin_elementor_auth_upload_rce",
  "is_install_path": true,
  "mod_time": "2022-10-03 14:43:12 +0000",
  "name": "Wordpress Plugin Elementor Authenticated Upload Remote Code Execution",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/wp_plugin_elementor_auth_upload_rce.rb",
  "platform": "PHP",
  "post_auth": true,
  "rank": 600,
  "ref_name": "multi/http/wp_plugin_elementor_auth_upload_rce",
  "references": [
    "EDB-50115",
    "CVE-2022-1329",
    "URL-https://www.wordfence.com/blog/2022/04/elementor-critical-remote-code-execution-vulnerability/",
    "URL-https://www.youtube.com/watch?v=tIhN1svzAYk"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Wordpress Elementor"
  ],
  "type": "exploit"
}
rank600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 21:42 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php",
  "author": [
    "Ramuel Gall",
    "AkuCyberSec",
    "h00die"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "The WordPress plugin Elementor versions 3.6.0 - 3.6.2, inclusive have a vulnerability\n          that allows any authenticated user to upload and execute any PHP file. This is achieved\n          by sending a request to install Elementor Pro from a user supplied zip file.\n          Any user with Subscriber or more permissions is able to execute this.\n          Tested against Elementor 3.6.1",
  "disclosure_date": "2022-03-29",
  "fullname": "exploit/multi/http/wp_plugin_elementor_auth_upload_rce",
  "is_install_path": true,
  "mod_time": "2022-10-03 14:43:12 +0000",
  "name": "Wordpress Plugin Elementor Authenticated Upload Remote Code Execution",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/wp_plugin_elementor_auth_upload_rce.rb",
  "platform": "PHP",
  "post_auth": true,
  "rank": 600,
  "ref_name": "multi/http/wp_plugin_elementor_auth_upload_rce",
  "references": [
    "EDB-50115",
    "CVE-2022-1329",
    "URL-https://www.wordfence.com/blog/2022/04/elementor-critical-remote-code-execution-vulnerability/",
    "URL-https://www.youtube.com/watch?v=tIhN1svzAYk"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Wordpress Elementor"
  ],
  "type": "exploit"
}

Text

The WordPress plugin Elementor versions 3.6.0 - 3.6.2, inclusive have a vulnerability that allows any authenticated user to upload and execute any PHP file. This is achieved by sending a request to install Elementor Pro from a user supplied zip file. Any user with Subscriber or more permissions is able to execute this. Tested against Elementor 3.6.1