Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

The Hacker News by The Hacker News
September 26, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananSep 26, 2026Vulnerability / Web Security

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.

The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions 4.3.0 and 4.3.1 of the plugin, which is active on over 10 million WordPress sites. Statistics from WordPress.org show that the two impacted versions alone have been installed on more than 2 million sites.

“One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform,” Patchstack said. “On a stock installation, an administrator clicking the link creates a second administrator account for the attacker.”

The WordPress security company said the attack does not hinge on any prerequisite, such as JavaScript, a submitted form, or a web page under the threat actor’s control. The link can even be a plain anchor tag embedded in an email, a chat message, or a comment.

Following responsible disclosure, the issue has been addressed in version 4.3.2 released earlier this week. A security researcher going by the alias “Saggre” has been credited with discovering and reporting the bug.

Patchstack said the vulnerability stems from the Editor Events module skipping CSRF protection for cookie-authenticated REST API requests every time the literal string “elementor/v1/events/” appears anywhere in the request URI.

“Because the request URI includes the query string, and the query string is written by whoever composes the link, any REST request can opt itself out of that protection by appending a harmless-looking parameter,” it added.

The bypass applies to the entire REST API surface of a site, including WordPress core routes and the routes of every other plugin installed on it. An attacker could exploit this loophole to create an administrator account through “/wp/v2/users” using a request like below –

https://example.com/wp-json/wp/v2/users
?_method=POST
&username=csrfadmin
&email=csrfadmin%40example.test
&password=...
&roles%5B%5D=administrator
&x=elementor/v1/events/

Because Elementor releases before 4.3.0 do not ship the Editor Events proxy, they are not affected by the flaw. Users of the plugin are advised to apply the latest update as soon as possible to counter any potential threat.



Source link

The Hacker News

The Hacker News

Next Post

Meta’s Muse Is Adults-Only. Why Does It Look Like a Kids’ Toy?

Recommended.

Forrester study shows why IT is key to building trust and scaling AI

Forrester study shows why IT is key to building trust and scaling AI

September 15, 2025
MIRhosting Expands Colocation Footprint with New Dedicated Data Rooms in Amsterdam

MIRhosting Expands Colocation Footprint with New Dedicated Data Rooms in Amsterdam

April 10, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio