CVE-2022-1329 is a remote code execution vulnerability in the Elementor Website Builder plugin for WordPress, affecting versions 3.6.0 through 3.6.2. The vulnerability arises from missing capability checks in the ~/core/app/modules/onboarding/module.php file, allowing unauthorized users to execute several AJAX actions. This flaw enables attackers to modify site data and upload malicious files, which can be leveraged to achieve remote code execution on the affected WordPress site.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting a vulnerability (CVE-2022-1329) in the Elementor WordPress plugin (versions 3.6.0-3.6.2). The exploit allows any authenticated user (Subscriber or higher) to upload and execute arbitrary PHP code by abusing the plugin's upload mechanism. The module logs in with provided credentials, retrieves a nonce from the profile page, and uploads a ZIP file containing a malicious PHP plugin via the admin-ajax.php endpoint. Upon successful exploitation, the attacker gains remote code execution as the web server user. The module is operational, leverages Metasploit's payload system, and leaves artifacts on disk (the uploaded plugin). The code is written in Ruby and is structured as a standard Metasploit exploit module.
This repository contains a proof-of-concept exploit for CVE-2022-1329, targeting the Elementor WordPress plugin versions 3.6.0, 3.6.1, and 3.6.2. The exploit leverages a broken access control vulnerability that allows any authenticated user to upload and activate a malicious plugin, resulting in remote code execution. The repository consists of a README.md with detailed vulnerability and exploitation instructions, and a Python script (exploit.py) that automates the attack. The script performs the following steps: logs in to the target WordPress site, retrieves a required nonce, uploads a ZIP file containing the attacker's PHP payload as a fake plugin, and optionally triggers the payload. The exploit does not include a payload; the user must supply a ZIP archive with the appropriate structure. The main endpoints targeted are the WordPress login page, the admin-ajax.php endpoint for plugin upload, and a page to activate the payload. The exploit is a POC and requires valid credentials for an account on the target WordPress site.
This repository contains a proof-of-concept exploit (exploit.py) and a README.md for CVE-2022-1329, a vulnerability in the WordPress Elementor plugin (versions 3.6.0, 3.6.1, 3.6.2) that allows any authenticated user to upload and execute arbitrary PHP code. The exploit requires valid WordPress credentials and a specially crafted ZIP file containing a malicious plugin. The Python script automates login, nonce extraction, file upload via the vulnerable AJAX endpoint, and payload activation. The README provides detailed vulnerability background, exploitation steps, and payload structure requirements. No actual payload is included; users must supply their own PHP code. The exploit targets WordPress installations with the vulnerable Elementor versions and leverages broken access control in the plugin's onboarding module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.