Elementor WordPress plugin flaw could let attackers create admin accounts

Patch released for CSRF bug affecting up to 2 million sites

By LineZotpaper
Published
Read Time2 min
A cross-site request forgery vulnerability in the popular Elementor Website Builder plugin for WordPress could allow unauthenticated attackers to create administrator accounts on affected sites, according to security firm Patchstack. The flaw impacts Elementor versions 4.3.0 and 4.3.1, which are used by up to 2 million websites, and a fix has been issued in version 4.3.2.

The vulnerability, a cross-site request forgery (CSRF) issue, can be exploited by tricking a logged-in administrator into opening a malicious link, causing their authenticated session to perform REST API actions permitted by their account. On default installations, Patchstack says the result is the creation of a new administrator account controlled by the attacker.

The Elementor Website Builder is a widely used WordPress plugin, active on 10 million websites, that lets users build sites through a drag-and-drop interface.

The flaw has not yet received a CVE identifier. According to Patchstack's analysis, the issue stems from the plugin's Editor Events module, which checks the raw request URI for the elementor/v1/events/ path and bypasses WordPress's REST nonce validation when that string is present. Because the URI also contains attacker-controlled query parameters, attackers can append the path to requests targeting other REST endpoints and trick logged-in users into executing them.

Patchstack reported the vulnerability to the Elementor team on September 22, crediting bug hunter "Saggre" for the discovery. Elementor released a fix two days later in version 4.3.2.

"One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform," Patchstack explained.

The security firm says the attack does not require JavaScript, an attacker-controlled webpage, or a submitted form, and the link can be delivered via email, chat message, or a site comment.

Patchstack notes that Elementor releases before 4.3.0 do not contain the affected Editor Events proxy, but those older versions are vulnerable to other flaws, some of which are already being actively exploited. Users are urged to upgrade to Elementor 4.3.2 as soon as possible.

§

Analysis

Why This Matters

  • Up to 2 million WordPress sites run the affected Elementor versions, making this a broad attack surface for one-click account takeover.
  • A successful exploit gives attackers full administrative control of a site, potentially enabling website defacement, malware distribution, or data theft.
  • The fix is available but depends on site administrators applying the update promptly; history suggests many WordPress sites remain unpatched for weeks or longer.

Background

Cross-site request forgery is a class of attack where a logged-in user is tricked into performing unintended actions on a site by a malicious link or embedded request. WordPress mitigates these attacks via nonce checks on REST API requests, but plugin bugs can occasionally bypass those protections. Elementor is one of the most widely installed WordPress page builders, making it an attractive target for attackers seeking broad impact. The plugin's maintainers have patched the specific flaw in version 4.3.2.

Key Perspectives

Elementor team: Responded quickly, releasing a fix within two days of being notified, and the advisory directs users to upgrade to 4.3.2 to block the bypass. Patchstack (researchers): Highlighted the simplicity and severity of the attack, noting the one-click exploitation and lack of requirement for JavaScript or user interaction beyond clicking a link. WordPress site administrators: Face a practical challenge — identifying whether they run the affected versions and rolling out the update across managed sites, especially in environments with custom code that may complicate upgrades. Critics/Skeptics: May note that the disclosure came without a CVE identifier yet and that older Elementor versions remain exposed to other vulnerabilities, suggesting the plugin's security track record still warrants caution.

What to Watch

  • Whether the flaw receives a CVE identifier and appears in widely used vulnerability scanning feeds.
  • Adoption rate of Elementor 4.3.2 among the up-to-2-million sites running the vulnerable versions.
  • Reports of exploitation in the wild — a common indicator of when attackers begin weaponizing a disclosed CSRF flaw.
  • Further patching announcements for older Elementor versions, which Patchstack says harbor other vulnerabilities.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.