Elementor CSRF in 4.3.0 and 4.3.1 Can Create Admins
Elementor 4.3.0 and 4.3.1 have a CSRF flaw a clicked admin link can use to create an attacker account; 4.3.2 fixes it.
Patchstack, BleepingComputer, and The Hacker News report an unauthenticated cross-site request forgery flaw in Elementor Website Builder 4.3.0 and 4.3.1, which Patchstack rates CVSS 8.8 and which has no assigned CVE. A single link opened by a logged-in WordPress user, including an administrator, can invoke REST API actions that account may perform and create an attacker-controlled administrator, without JavaScript. Patchstack says releases before 4.3.0 do not include the vulnerable Editor Events proxy and that a hidden Editor Events experiment is on by default for newer installs; BleepingComputer says the module matches elementor/v1/events/ in the raw request URI and skips WordPress REST nonce checks. Researcher Saggre reported the issue, Patchstack shipped mitigation rules, and Elementor fixed it in 4.3.2 after a September 22 report. Neither source describes this bug as exploited, though BleepingComputer says separate flaws in older versions are. Affected-site counts differ: Patchstack’s headline and The Hacker News say more than two million of more than 10 million active installs, while BleepingComputer says up to about 2 million of 10 million.
- Only Elementor Website Builder 4.3.0 and 4.3.1 are affected; releases before 4.3.0 do not include the vulnerable Editor Events proxy.
- Patchstack rates the unauthenticated CSRF flaw CVSS 8.8; no CVE is assigned.
- One link opened by a logged-in WordPress administrator can create an attacker-controlled admin account without JavaScript.
- BleepingComputer says the Editor Events module matches elementor/v1/events/ in the raw request URI and skips WordPress REST nonce checks; Patchstack says a hidden Editor Events experiment is on by default for newer installs.
- Researcher Saggre reported the issue; Elementor fixed it in 4.3.2 after a September 22 report, and Patchstack shipped mitigation rules.
- This bug is not described as exploited, though BleepingComputer says separate flaws in older versions are.
- Install counts disagree: Patchstack’s headline and The Hacker News say more than 2 million of more than 10 million active sites, while BleepingComputer says up to about 2 million of 10 million.
Coverage timelineoldest first · each row is one article
- · 1d agoCross-Site Request Forgery in Elementor Plugin Affecting 2 Million+ Sites
Patchstack· 76
Elementor 4.3.0 and 4.3.1 have a CVSS 8.8 CSRF bug that can create a new administrator account.
- · 1d agoElementor WordPress flaw lets attackers create admin accounts
BleepingComputer· 66
Elementor 4.3.0 and 4.3.1 CSRF bug lets a malicious link create WordPress admin accounts.
- · 22h agoElementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
The Hacker News· 66
Elementor CSRF in versions 4.3.0 and 4.3.1 can create admin accounts after one clicked link.