Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
AI-summarised brief · reviewed before publication
A high‑severity CSRF flaw in Elementor’s WordPress plugin (versions 4.3.0 and 4.3.1) allows an unauthenticated attacker to create rogue administrator accounts by sending a crafted link. The vulnerability, scoring 8.8 on CVSS, bypasses CSRF checks for any REST API request containing “elementor/v1/events/” in the URI. Over 10 million sites run Elementor, with more than 2 million using the affected releases. The flaw was disclosed by researcher “Saggre” and patched in version 4.3.2.
💡 Why It Matters
- · The flaw enables attackers to gain full site control without user interaction beyond clicking a link, exposing millions of WordPress sites to rapid takeover and potential data exfiltration.