Critical Elementor CSRF Flaw Lets Attackers Create Admin Accounts on 2M+ Sites
A critical cross-site request forgery vulnerability in Elementor versions 4.3.0 and 4.3.1 allows attackers to create administrator accounts on WordPress sites with the Editor Events experimental feature enabled. The flaw stems from a flawed partial URL match in the REST API authentication filter, which bypasses WordPress nonce validation when a crafted link is opened by a logged-in administrator. An attacker only needs to trick an authenticated administrator into clicking a specially constructed URL, after which the WordPress REST API processes the malicious request using the victim's own session credentials. Patchstack, which published the disclosure on September 25, 2026, assigned a CVSS score of 8.8, though the overall impact is assessed as critical given the potential for full site takeover. No active exploitation has been reported, and users are advised to update immediately to Elementor version 4.3.2 or later.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in