Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-1329 — CVE-2022-1329 exploit for WordPress Elementor plugin (3.6.0-3.6.2) enabling authenticated remote code execution via missing capability check and malicious file upload. | Kitploit
Tools/GitHubGitHub/dexit/cve-2022-1329
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationRemote Access ToolPayload Development
GitHubdexit/cve-2022-1329

CVE-2022-1329

CVE-2022-1329 exploit for WordPress Elementor plugin (3.6.0-3.6.2) enabling authenticated remote code execution via missing capability check and malicious file upload.

View Repository
53 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-1329

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

authenticationcomplexityvector
SINGLELOWNETWORK
confidentialityintegrityavailability
PARTIALPARTIALPARTIAL

CVSS Score: 6.5

References

  • https://plugins.trac.wordpress.org/changeset/2708766/elementor/trunk/core/app/modules/onboarding/module.php

  • https://www.wordfence.com/blog/2022/04/elementor-critical-remote-code-execution-vulnerability/

  • https://www.pluginvulnerabilities.com/2022/04/12/5-million-install-wordpress-plugin-elementor-contains-authenticated-remote-code-execution-rce-vulnerability/

  • http://packetstormsecurity.com/files/168615/WordPress-Elementor-3.6.2-Shell-Upload.html

Brut File

  • CVE-2022-1329.json

External Repositories

NameLink
CVE-2022-1329CVE-2022-1329
CVE-2022-1329-WordPress-Elementor-3.6.0-3.6.1-3.6.2-Remote-Code-Execution-ExploitCVE-2022-1329-WordPress-Elementor-3.6.0-3.6.1-3.6.2-Remote-Code-Execution-Exploit
CVE-2022-1329-WordPress-Elementor-RCECVE-2022-1329-WordPress-Elementor-RCE

About this repository

This repository is part of the project Live Hack CVE. Made by Sn0wAlice for the people that care about security and need to have a feed of the latest CVEs. Hope you enjoy it, don't forget to star the repo and follow me on Twitter and Github

Download Tool