chiprook
← Security
SecuritySeptember 26, 2026, 01:13

Elementor WordPress flaw lets attackers create admin accounts

A CSRF vulnerability in the Elementor Website Builder plugin for WordPress lets an unauthenticated attacker create an administrator account by tricking a logged-in admin into opening a malicious link. Versions 4.3.0 and 4.3.1 are affected (up to 2 million sites); a fix shipped in 4.3.2.

Elementor WordPress flaw lets attackers create admin accounts
#WordPress#Elementor#Patchstack
Read next
Security

Default Join Key Let Attackers Mint Admin Tokens on JFrog Artifactory

Security

cPanel flaw lets a hosting account run code as root and take over the server

Security

Forminator WordPress plugin hit by 9.1-severity vulnerability

Security

Malicious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites