Elementor plugin bug allows site takeover via CSRF

A high-severity cross-site request forgery vulnerability in the Elementor Website Builder plugin for WordPress can let an unauthenticated attacker create administrator accounts and seize control of a site. The flaw has a CVSS score of 8.8 and has not yet received a CVE identifier. Exploitation requires an administrator to click a crafted link, and only certain plugin versions are affected.
The story concerns a WordPress plugin, Elementor Website Builder, and a cross-site request forgery flaw rated high severity at 8.8. Per the available summary, someone with no prior access could add privileged accounts and gain control of a site, provided a site administrator follows a specially made link. The issue has no CVE identifier yet, and it is limited to some releases of the plugin. This fits the wider pattern of web-plugin security problems that hinge on user interaction and prompt updates.
Site owners, administrators, and organizations relying on affected WordPress sites could be most directly impacted if the flaw is exploited. An attacker gaining administrative access may be able to control site content or operations, potentially disrupting services and undermining visitor trust. Because exploitation requires an administrator to follow a specially made link, exposure may depend on user awareness and maintenance practices. The absence of a CVE and the version-specific nature of the issue could also affect how quickly defenders identify and address it.