hacker-news · Crawled Sep 26, 2026

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

1 IoCs
Read original article ↗

AI Summary

A high-severity CSRF vulnerability in Elementor Website Builder WordPress plugin versions 4.3.0 and 4.3.1 allows unauthenticated attackers to take over WordPress sites by tricking an authenticated administrator into clicking a crafted link. The flaw bypasses CSRF protection for cookie-authenticated REST API requests when the string 'elementor/v1/events/' appears in the request URI, enabling actions like creating rogue administrator accounts. The vulnerability affects over 2 million sites and has been patched in version 4.3.2.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Filename elementor/v1/events/ Details →