
Proof-of-concept exploit for CVE-2023-47504 targeting Elementor WordPress plugin. Requires subscriber credentials and wp-config.php access to delete elementor cache files.
Exploit for CVE-2023-47504.
According to NIST, this vulnerability should allow unauthenticated users to access functionalities in the Elementor Website Builder Plugin.
Based on my research into the vulnerability, and also judging by the URL from Patchstack that describes the vulnerability: https://patchstack.com/database/vulnerability/elementor/wordpress-elementor-plugin-3-16-4-contributor-arbitrary-attachment-read-vulnerability?_s_id=cve, I recon this is actually requires credentials for at least a subscriber account.
Also, for the exploit to work one needs access to the wp-config.php file of the target website.
wp-config.phpwp-admin/profile.php and update your profile;wordpress_logged_in_* cookie and your user id from the request;wp-config.phppython exploit.py --target <TARGET> --wordpress-cookie <COPIED COOKIE> --uid <COPIED USER ID> --salt <COPIED SALT>;/wp-content/uploads/elementor/css);