hacker-news · Crawled Sep 26, 2026
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
1 IoCs
Read original article ↗
AI Summary
A high-severity CSRF vulnerability in Elementor Website Builder WordPress plugin versions 4.3.0 and 4.3.1 allows unauthenticated attackers to take over WordPress sites by tricking an authenticated administrator into clicking a crafted link. The flaw bypasses CSRF protection for cookie-authenticated REST API requests when the string 'elementor/v1/events/' appears in the request URI, enabling actions like creating rogue administrator accounts. The vulnerability affects over 2 million sites and has been patched in version 4.3.2.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | elementor/v1/events/ | Details → |