← Back to browse · API

CVE-2022-1329

Severity
HIGH
CVSS
8.8
EPSS
0.92658
Risk score
67.63
CISA KEV
No
PoC
No
Published
2022-04-19
Modified
2025-02-07
First seen
2026-08-07
Aliases
EUVD-2022-24657, GHSA-87W4-XWRV-8VJ5
Products
Elementor:Elementor Website Builder 3.6.0, Elementor:Elementor Website Builder 3.6.1, Elementor:Elementor Website Builder 3.6.2
Sources
euvd EUVD-2022-24657

Description

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

References