Elementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code Execution
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 8.8epss 93%
from disclosure to weapon794 days
Published on NVDApr 19
1st PoC+794d
metasploitMar 29
VulnCheckApr 13
exploitation probability
93%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
elemntor · Elementor Website Builderpublic PoCs found — 1
vulncheckvulncheck.com/xdb/0f5c17f7f62eunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/168615/WordPress-Elementor-3.6.2-Shell-Upload.htmlhttps://plugins.trac.wordpress.org/changeset/2708766/elementor/trunk/core/app/modules/onboarding/module.phphttps://www.pluginvulnerabilities.com/2022/04/12/5-million-install-wordpress-plugin-elementor-contains-authenticated-remote-code-execution-rce-vulnerability/https://www.wordfence.com/blog/2022/04/elementor-critical-remote-code-execution-vulnerability/