The vulnerability, a cross-site request forgery (CSRF) issue, can be exploited by tricking a logged-in administrator into opening a malicious link, causing their authenticated session to perform REST API actions permitted by their account. On default installations, Patchstack says the result is the creation of a new administrator account controlled by the attacker.
The Elementor Website Builder is a widely used WordPress plugin, active on 10 million websites, that lets users build sites through a drag-and-drop interface.
The flaw has not yet received a CVE identifier. According to Patchstack's analysis, the issue stems from the plugin's Editor Events module, which checks the raw request URI for the elementor/v1/events/ path and bypasses WordPress's REST nonce validation when that string is present. Because the URI also contains attacker-controlled query parameters, attackers can append the path to requests targeting other REST endpoints and trick logged-in users into executing them.
Patchstack reported the vulnerability to the Elementor team on September 22, crediting bug hunter "Saggre" for the discovery. Elementor released a fix two days later in version 4.3.2.
"One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform," Patchstack explained.
The security firm says the attack does not require JavaScript, an attacker-controlled webpage, or a submitted form, and the link can be delivered via email, chat message, or a site comment.
Patchstack notes that Elementor releases before 4.3.0 do not contain the affected Editor Events proxy, but those older versions are vulnerable to other flaws, some of which are already being actively exploited. Users are urged to upgrade to Elementor 4.3.2 as soon as possible.