Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: cross-site-request-forgery (2 articles)Clear

Elementor WordPress plugin flaw lets one link create a rogue administrator account

Patchstack detailed a high-severity cross-site request forgery flaw, rated 8.8 and not yet assigned a CVE, in the Elementor Website Builder WordPress plugin, which is active on over ten million sites. It affects only versions 4.3.0 and 4.3.1, installed on more than two million sites, and is fixed in 4.3.2. One link opened by a logged-in WordPress user makes that user perform any REST API action their account permits, so an administrator clicking it creates a second administrator account for the attacker on a stock install. The attack needs no JavaScript, submitted form, or attacker-controlled page; the link can be a plain anchor tag in an email, chat, or comment.

Check
Update the Elementor plugin to 4.3.2 across all WordPress sites, then audit administrator accounts for unexpected additions created via the flaw.
Affected
Sites running Elementor 4.3.0 or 4.3.1 let an unauthenticated attacker trick a logged-in admin into creating a rogue administrator account by clicking a link.
Fix
Apply Elementor 4.3.2, remove unrecognized admin accounts, and warn administrators against opening untrusted links while signed in to WordPress.

WordPress flaw forces theme installs and can chain to server code execution

WordPress shipped 7.1.1 on September 17 to fix a flaw that pwn.ai calls Click2Shell, where a crafted link opened by a logged-in administrator installs a theme from the official directory with no click. Two parts of WordPress read the link differently, so attacker-added characters steer the admin browser into clicking Install, and the logged-in session supplies the permission and security token. Alone it only installs a real, switched-off theme, but the researchers chained it with a second flaw in the Mobile Repair Zone theme, whose handler fetched and ran remote code during a Customizer preview, reaching server code execution. No in-the-wild abuse is reported.

Check
Update all WordPress sites to 7.1.1 immediately, then audit installed themes for unexpected additions and remove any that administrators did not intend.
Affected
Sites where an administrator opens a crafted link can silently install an attacker-chosen theme, which can chain with a vulnerable theme to code execution.
Fix
Apply 7.1.1, remove unused themes, and warn administrators against opening untrusted links while authenticated to the WordPress dashboard.