Wordpress Plugin Elementor Authenticated Upload Remote Code Execution

cve CVE-2022-1329 1 source, 1 claim · Watch

Metasploit exploit modules writes:
The WordPress plugin Elementor versions 3.6.0 - 3.6.2, inclusive have a vulnerability that allows any authenticated user to upload and execute any PHP file. This is achieved by sending a request to install Elementor Pro from a user supplied zip file. Any user with Subscriber or more permissions is able to execute this. Tested against Elementor 3.6.1 the claim

What each source says

PropertySourceSaidMeans here
Platform
platform
Metasploit exploit modulesPHP
receipt
Source
Metasploit exploit modules
Its words
PHP
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 19:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php",
  "author": [
    "Ramuel Gall",
    "AkuCyberSec",
    "h00die"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "The WordPress plugin Elementor versions 3.6.0 - 3.6.2, inclusive have a vulnerability\n          that allows any authenticated user to upload and execute any PHP file. This is achieved\n          by sending a request to install Elementor Pro from a user supplied zip file.\n          Any user with Subscriber or more permissions is able to execute this.\n          Tested against Elementor 3.6.1",
  "disclosure_date": "2022-03-29",
  "fullname": "exploit/multi/http/wp_plugin_elementor_auth_upload_rce",
  "is_install_path": true,
  "mod_time": "2022-10-03 14:43:12 +0000",
  "name": "Wordpress Plugin Elementor Authenticated Upload Remote Code Execution",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/wp_plugin_elementor_auth_upload_rce.rb",
  "platform": "PHP",
  "post_auth": true,
  "rank": 600,
  "ref_name": "multi/http/wp_plugin_elementor_auth_upload_rce",
  "references": [
    "EDB-50115",
    "CVE-2022-1329",
    "URL-https://www.wordfence.com/blog/2022/04/elementor-critical-remote-code-execution-vulnerability/",
    "URL-https://www.youtube.com/watch?v=tIhN1svzAYk"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Wordpress Elementor"
  ],
  "type": "exploit"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-04 19:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php",
  "author": [
    "Ramuel Gall",
    "AkuCyberSec",
    "h00die"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "The WordPress plugin Elementor versions 3.6.0 - 3.6.2, inclusive have a vulnerability\n          that allows any authenticated user to upload and execute any PHP file. This is achieved\n          by sending a request to install Elementor Pro from a user supplied zip file.\n          Any user with Subscriber or more permissions is able to execute this.\n          Tested against Elementor 3.6.1",
  "disclosure_date": "2022-03-29",
  "fullname": "exploit/multi/http/wp_plugin_elementor_auth_upload_rce",
  "is_install_path": true,
  "mod_time": "2022-10-03 14:43:12 +0000",
  "name": "Wordpress Plugin Elementor Authenticated Upload Remote Code Execution",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/wp_plugin_elementor_auth_upload_rce.rb",
  "platform": "PHP",
  "post_auth": true,
  "rank": 600,
  "ref_name": "multi/http/wp_plugin_elementor_auth_upload_rce",
  "references": [
    "EDB-50115",
    "CVE-2022-1329",
    "URL-https://www.wordfence.com/blog/2022/04/elementor-critical-remote-code-execution-vulnerability/",
    "URL-https://www.youtube.com/watch?v=tIhN1svzAYk"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Wordpress Elementor"
  ],
  "type": "exploit"
}
—

exploit

Wordpress Plugin Elementor Authenticated Upload Remote Code Execution
zetlyn/cve-metasploit · 2022-03-29
platform PHP rank 600 source