bleeping-computer · Crawled Sep 25, 2026
Elementor WordPress flaw lets attackers create admin accounts
Read original article ↗AI Summary
A cross-site request forgery (CSRF) vulnerability in Elementor plugin versions 4.3.0 and 4.3.1 for WordPress allows unauthenticated attackers to create administrator accounts by tricking a logged-in administrator into opening a malicious link. The flaw exists in the Editor Events module, which bypasses WordPress REST nonce validation when the request URI contains the 'elementor/v1/events/' path, enabling attackers to append this path via query parameters to trigger unauthorized REST API actions. The vulnerability was reported by security firm Patchstack and patched in version 4.3.2, with no CVE assigned at the time of reporting.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.