MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-26 · via The Hacker News

Elementor plugin bug allows site takeover via CSRF

Image via The Hacker News
Image via The Hacker News

A high-severity cross-site request forgery vulnerability in the Elementor Website Builder plugin for WordPress can let an unauthenticated attacker create administrator accounts and seize control of a site. The flaw has a CVSS score of 8.8 and has not yet received a CVE identifier. Exploitation requires an administrator to click a crafted link, and only certain plugin versions are affected.

Expanded Detail

The story concerns a WordPress plugin, Elementor Website Builder, and a cross-site request forgery flaw rated high severity at 8.8. Per the available summary, someone with no prior access could add privileged accounts and gain control of a site, provided a site administrator follows a specially made link. The issue has no CVE identifier yet, and it is limited to some releases of the plugin. This fits the wider pattern of web-plugin security problems that hinge on user interaction and prompt updates.

Context

Site owners, administrators, and organizations relying on affected WordPress sites could be most directly impacted if the flaw is exploited. An attacker gaining administrative access may be able to control site content or operations, potentially disrupting services and undermining visitor trust. Because exploitation requires an administrator to follow a specially made link, exposure may depend on user awareness and maintenance practices. The absence of a CVE and the version-specific nature of the issue could also affect how quickly defenders identify and address it.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
WordPress Core Vulnerability Allows Remote Code Execution Under Specific Conditions · Cybersecurity
Roundcube Webmail SQL Injection Bug Exploited Before Patch · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link.” Browse more stories.