Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
thehackernews.com Sep 26, 2026

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

AI-summarised brief · reviewed before publication

A high‑severity CSRF flaw in Elementor’s WordPress plugin (versions 4.3.0 and 4.3.1) allows an unauthenticated attacker to create rogue administrator accounts by sending a crafted link. The vulnerability, scoring 8.8 on CVSS, bypasses CSRF checks for any REST API request containing “elementor/v1/events/” in the URI. Over 10 million sites run Elementor, with more than 2 million using the affected releases. The flaw was disclosed by researcher “Saggre” and patched in version 4.3.2.

💡 Why It Matters

  • · The flaw enables attackers to gain full site control without user interaction beyond clicking a link, exposing millions of WordPress sites to rapid takeover and potential data exfiltration.