References https://nvd.nist.gov/vuln/detail/CVE-2022-1329 https://www.wordfence.com/blog/2022/04/elementor-critical-remote-code-execution-vulnerability/ https://www.sentinelone.com/vulnerability-database/cve-2022-1329/ https://www.rapid7.com/db/vulnerabilities/elementor-plugin-cve-2022-1329/ https://medium.com/@_crac/cve-2022-1329-rce-in-wordpress-plugin-elementor-7af3d92a7b90 https://github.com/dexit/CVE-2022-1329 https://attackerkb.com/topics/w7gwhV88le/cve-2022-1329 https://www.tenable.com/cve/CVE-2022-1329 https://www.cve.org/CVERecord?id=CVE-2022-1329 https://wpscan.com/vulnerability/df62d170-c7d1-43a4-b6dc-20512934c33e/ https://www.exploit-db.com/exploits/50882 https://github.com/Grazee/CVE-2022-1329-WordPress-Elementor-RCE
Related VulnerabilitiesPoCCVE-2026-5524: Divi Form Builder <=5.1.8 - Unauthenticated Arbitrary File Upload RCEPoCCVE-2026-59177: ESPHome Device Builder <1.0.10 - Unauthenticated Dashboard AccessPoCCVE-2026-32475: Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form HandlerWordpress Events Calendar插件敏感信息泄露漏洞(CVE-2025-9808)WordPress Directory Kit 插件敏感信息泄露漏洞(CVE-2025-13920)PoCCVE-2025-14998: Branda WordPress plugin - Privilege EscalationPoCCVE-2022-1281: Photo Gallery WordPress v1.6.3 - SQL InjectionPoCCVE-2026-12394: WordPress MemberGlut < 1.1.5 - Unauthenticated Privilege EscalationPoCCVE-2026-15826: User Profile Builder 3.16.4 - Unauthenticated Authentication BypassPoCsimple-file-list-rce: WordPress Simple File List <=4.2.2 - Remote Code ExecutionPoCCVE-2025-13528: Feedback Modal for Website <= 1.0.1 - Unauthenticated Feedback ExportPoCCVE-2026-13147: WordPress Kirki < 6.0.12 - Server-Side Request ForgeryPoCCVE-2026-14894: WordPress Super Forms <= 6.3.313 - Arbitrary File Upload