Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: elementor (1 article)Clear

Elementor WordPress plugin flaw lets one link create a rogue administrator account

Patchstack detailed a high-severity cross-site request forgery flaw, rated 8.8 and not yet assigned a CVE, in the Elementor Website Builder WordPress plugin, which is active on over ten million sites. It affects only versions 4.3.0 and 4.3.1, installed on more than two million sites, and is fixed in 4.3.2. One link opened by a logged-in WordPress user makes that user perform any REST API action their account permits, so an administrator clicking it creates a second administrator account for the attacker on a stock install. The attack needs no JavaScript, submitted form, or attacker-controlled page; the link can be a plain anchor tag in an email, chat, or comment.

Check
Update the Elementor plugin to 4.3.2 across all WordPress sites, then audit administrator accounts for unexpected additions created via the flaw.
Affected
Sites running Elementor 4.3.0 or 4.3.1 let an unauthenticated attacker trick a logged-in admin into creating a rogue administrator account by clicking a link.
Fix
Apply Elementor 4.3.2, remove unrecognized admin accounts, and warn administrators against opening untrusted links while signed in to WordPress.