MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-25 · via BleepingComputer

Elementor CSRF bug could let attackers add WordPress admin users

Image via BleepingComputer
Image via BleepingComputer

A CSRF bug in Elementor versions 4.3.0 and 4.3.1 can let an unauthenticated attacker create administrator accounts by luring a logged-in admin to a crafted link. The flaw stems from the Editor Events module bypassing WordPress REST nonce validation when a specific path appears in the request URI. Patchstack reported it and Elementor fixed it in 4.3.2; up to 2 million sites may be affected.

Expanded Detail

Elementor 4.3.0 and 4.3.1 contain a CSRF weakness in the Editor Events component. It examines the request URI for a particular path and skips WordPress REST nonce checks when that string is present. Since query parameters are attacker-controlled, the path can be attached to other REST calls.

Patchstack received the report from researcher Saggre and alerted Elementor on Sept 22. A fix arrived two days later in 4.3.2. WordPress.org data suggests as many as 2 million sites run the vulnerable releases. Older versions lack this proxy but have separate known issues.

Context

The flaw could affect site owners, visitors, and businesses relying on WordPress. If an administrator opens a crafted link, an attacker may gain full control, potentially enabling defacement, data theft, or malware distribution. With up to 2 million sites on vulnerable versions, the exposure may be broad, though exploitation requires a logged-in admin to click the link. Rapid patching to 4.3.2 could reduce risk.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Elementor plugin bug allows site takeover via CSRF · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Elementor WordPress flaw lets attackers create admin accounts.” Browse more stories.