Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions 4.3.0 and 4.3.1 of the plugin, which is active on over 10 million WordPress sites. Statistics from WordPress.org show that the two impacted versions alone have been installed on more than 2 million sites. "One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform," Patchstack said . "On a stock installation, an administrator clicking the link creates a second administrator account for the attacker." The WordPress security company said the attack does not hinge on any prerequisite, such as JavaScrip...
Sep 26, 2026