Elementor CSRF bug could let attackers add WordPress admin users

A CSRF bug in Elementor versions 4.3.0 and 4.3.1 can let an unauthenticated attacker create administrator accounts by luring a logged-in admin to a crafted link. The flaw stems from the Editor Events module bypassing WordPress REST nonce validation when a specific path appears in the request URI. Patchstack reported it and Elementor fixed it in 4.3.2; up to 2 million sites may be affected.
Elementor 4.3.0 and 4.3.1 contain a CSRF weakness in the Editor Events component. It examines the request URI for a particular path and skips WordPress REST nonce checks when that string is present. Since query parameters are attacker-controlled, the path can be attached to other REST calls.
Patchstack received the report from researcher Saggre and alerted Elementor on Sept 22. A fix arrived two days later in 4.3.2. WordPress.org data suggests as many as 2 million sites run the vulnerable releases. Older versions lack this proxy but have separate known issues.
The flaw could affect site owners, visitors, and businesses relying on WordPress. If an administrator opens a crafted link, an attacker may gain full control, potentially enabling defacement, data theft, or malware distribution. With up to 2 million sites on vulnerable versions, the exposure may be broad, though exploitation requires a logged-in admin to click the link. Rapid patching to 4.3.2 could reduce risk.