Elementor WordPress flaw lets attackers create admin accounts
A CSRF vulnerability in the Elementor Website Builder plugin for WordPress lets an unauthenticated attacker create an administrator account by tricking a logged-in admin into opening a malicious link. Versions 4.3.0 and 4.3.1 are affected (up to 2 million sites); a fix shipped in 4.3.2.
- Only Elementor 4.3.0 and 4.3.1 are affected — up to 2 million sites
- One-click attack: opening a link as an admin is enough
- Fix released on September 24 in version 4.3.2
- Plugin is active on 10 million sites; no JavaScript required
Read next
Security