Skip to content
Critical CSRF Vulnerability in Elementor Plugin Allows Unauthorized Admin Account Creation

Critical CSRF Vulnerability in Elementor Plugin Allows Unauthorized Admin Account Creation

First seen 26 Sep 2026, 14:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 16:34 UTC
  • •CSRF vulnerability in Elementor allows admin account creation via malicious links.
  • •Affected versions 4.3.0 and 4.3.1 are used by approximately 2 million sites.
  • •Patchstack reported the issue, and Elementor released a fix in version 4.3.2.

A serious Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Elementor Website Builder plugin for WordPress, affecting versions 4.3.0 and 4.3.1. This flaw allows unauthenticated attackers to create administrator accounts by tricking logged-in users into clicking a malicious link. The vulnerability impacts approximately 2 million sites using these versions of the plugin, which is active on over 10 million sites globally. The issue arises from Elementor's Editor Events module bypassing WordPress's REST nonce validation when a specific string is present in the request URI. Patchstack reported the vulnerability to Elementor on September 22, leading to a fix being released on September 24 in version 4.3.2. Users are urged to update immediately to mitigate potential exploitation. The vulnerability has not yet been assigned a CVE identifier.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-22
Vulnerability reported to Elementor
Patchstack informed Elementor of the CSRF vulnerability discovered by researcher Saggre.
Bleepingcomputer
2026-09-24
Patch released for Elementor
Elementor released version 4.3.2 to address the CSRF vulnerability and prevent exploitation.
Thehackernews
2026-09-26
Public disclosure of vulnerability details
Multiple cybersecurity outlets reported on the CSRF vulnerability and its implications for site security.
Patchstack

More articles in this cluster (4)