patchstack.com Critical CSRF Vulnerability in Elementor Plugin Allows Unauthorized Admin Account Creation
Article Content
- •CSRF vulnerability in Elementor allows admin account creation via malicious links.
- •Affected versions 4.3.0 and 4.3.1 are used by approximately 2 million sites.
- •Patchstack reported the issue, and Elementor released a fix in version 4.3.2.
A serious Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Elementor Website Builder plugin for WordPress, affecting versions 4.3.0 and 4.3.1. This flaw allows unauthenticated attackers to create administrator accounts by tricking logged-in users into clicking a malicious link. The vulnerability impacts approximately 2 million sites using these versions of the plugin, which is active on over 10 million sites globally. The issue arises from Elementor's Editor Events module bypassing WordPress's REST nonce validation when a specific string is present in the request URI. Patchstack reported the vulnerability to Elementor on September 22, leading to a fix being released on September 24 in version 4.3.2. Users are urged to update immediately to mitigate potential exploitation. The vulnerability has not yet been assigned a CVE identifier.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
Critical OVERPASS Vulnerability in SAP Kernel Requires Immediate Action On September 8, 2026, SAP released security updates addressing 20 vulnerabilities, including a critical memory corruption flaw tracked as CVE-2026-44756, named OVERPASS. This vulnerability allows unauthenticated attackers to execute arbitrary commands on vulnerable SAP systems, leading to full compromise of business…
Critical CSRF Vulnerability in WWBN AVideo Exposes Admins to Attacks A cross-site request forgery (CSRF) vulnerability has been identified in WWBN AVideo, specifically in the deleteHistory.json.php and finishAll.json.php files. This flaw allows unauthenticated attackers to manipulate live history by sending GET requests without CSRF token validation. The vulnerability affects…