Patchstack detailed a high-severity cross-site request forgery flaw, rated 8.8 and not yet assigned a CVE, in the Elementor Website Builder WordPress plugin, which is active on over ten million sites. It affects only versions 4.3.0 and 4.3.1, installed on more than two million sites, and is fixed in 4.3.2. One link opened by a logged-in WordPress user makes that user perform any REST API action their account permits, so an administrator clicking it creates a second administrator account for the attacker on a stock install. The attack needs no JavaScript, submitted form, or attacker-controlled page; the link can be a plain anchor tag in an email, chat, or comment.