Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Elementor CSRF in versions 4.3.0 and 4.3.1 can create admin accounts after one clicked link.
A high-severity cross-site request forgery flaw in Elementor Website Builder 4.3.0 and 4.3.1 can let an unauthenticated attacker create a WordPress administrator if a logged-in admin opens a crafted link. Patchstack rated it CVSS 8.8, and no CVE has been assigned. The plugin is active on more than 10 million sites, with the two vulnerable versions installed on more than 2 million. The issue is fixed in 4.3.2; releases before 4.3.0 are not affected.