Elementor CSRF Flaw Turns One Admin Click Into a Rogue WordPress Administrator Account
A bug in Elementor 4.3.0 and 4.3.1 lets an attacker create a new WordPress administrator account when a logged-in admin clicks a single malicious link. Version 4.3.2 fixes it.

One click on the wrong link is all it takes to hand a stranger full control of a WordPress site running a recent version of Elementor. The page builder, active on roughly 10 million sites, shipped a cross-site request forgery flaw that lets an unauthenticated attacker create their own administrator account.
The damage is contained to two releases. Only Elementor 4.3.0 and 4.3.1 are affected, which still covers up to about 2 million sites, BleepingComputer reports.
The attack is almost insultingly simple. A logged-in admin opens a crafted link, sent by email, chat, or left in a comment. Their own session then performs a REST API action on the attacker's behalf, and on default installs that action creates a new administrator the attacker controls. No JavaScript, no attacker-hosted page, no form.
The root cause sits in Elementor's Editor Events module. According to Patchstack, the module checks the raw request URI for the string elementor/v1/events/ and, when it finds it, skips WordPress's REST nonce validation. An attacker can append that path through query parameters to entirely different REST endpoints, and the nonce check simply never runs.
Researcher Saggre reported the bug through Patchstack on September 22. Elementor shipped version 4.3.2 with a fix two days later, SC Media notes. No CVE identifier had been assigned at disclosure.
Sites on older releases do not have this particular proxy, but that is cold comfort, since earlier versions carry other flaws, some of them already exploited in the wild. The fix is to move to 4.3.2.
It is the latest reminder that plugins and extensions are where web platforms keep getting hurt, from WordPress to the StyleSmuggler bug in Magento and Adobe Commerce.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free