Mastodon Mastodon Mastodon Mastodon

Elementor CSRF vulnerability in WordPress plugin lets attackers create an admin with a single link click

Photo of author

CyberSecureFox Editorial Team

Published:

A Elementor Website Builder plugin for WordPress has been found to contain a CSRF (cross-site request forgery) vulnerability which, according to Patchstack, allows an unauthenticated attacker to create an administrator account on a target site — it is enough for a logged‑in administrator to click a specially crafted link. Versions 4.3.0 and 4.3.1 of the plugin are affected. According to WordPress.org, Elementor is installed on more than 10 million sites. A fix is available in version 4.3.2, released this week.

Technical details of the vulnerability

As stated in Patchstack’s analysis, the root cause lies in the Editor Events module, which appeared in Elementor starting from version 4.3.0. According to the researchers, this module disables CSRF protection for REST API requests with cookie authentication whenever the request URI contains the string elementor/v1/events/.

The key nuance: the request URI includes the query string, which is formed by the sender of the link. This means an attacker can add the trigger string as a seemingly harmless parameter to any REST request, thereby disabling CSRF checks for it. The report provides an example of a request to create an administrator via the standard WordPress route /wp/v2/users with an additional parameter &x=elementor/v1/events/.

It is important to emphasize that, according to Patchstack, the bypass applies not only to Elementor’s own endpoints, but potentially to the entire REST API surface of the site — including WordPress core routes and routes of other installed plugins. This significantly expands the impact radius compared to a typical vulnerability in an individual plugin. However, it should be noted that this statement about the expanded impact radius is based on a single source and has not been independently confirmed.

According to the same report, the attack does not require JavaScript, form submission, or control over a web page — the link can be a simple HTML <a> tag embedded in an email, chat message, or comment. A CVE identifier has not been assigned to the vulnerability at the time of publication. Elementor versions prior to 4.3.0 reportedly do not contain the Editor Events module and are not affected by this issue.

Scope and impact assessment

Elementor is one of the most widely used page builders for WordPress. The confirmed figure is more than 10 million active installations. The vulnerability affects a narrow range of versions (4.3.0 and 4.3.1), but these versions were the current ones until the patch was released, which means a high likelihood of their presence on a significant number of sites.

The highest risk is for sites where administrators are actively working in the WordPress dashboard and might click a link in an email or messenger while logged in. Successful exploitation gives an attacker full control over the site — from modifying content to implanting malicious code and stealing user data.

It is worth noting that, so far, there have been no recorded cases of this vulnerability being actively exploited in the wild. Elementor’s official security page on GitHub does not contain any published security advisories, and no dedicated vendor bulletin could be found.

Mitigation recommendations

  • Immediately update Elementor to version 4.3.2 — this is the primary and sufficient measure. The update is available via the standard WordPress plugin update mechanism.
  • Check the current version of the plugin on all sites you manage. If version 4.3.0 or 4.3.1 is installed, updating is a priority.
  • Review the list of site administrators for any unknown accounts, especially if the update was delayed.
  • Analyze your web server and WordPress logs: if the described attack mechanism is accurate, signs of exploitation may appear as cookie‑authenticated REST requests whose URI or query string contains elementor/v1/events/ — in particular, requests to the /wp/v2/users endpoint used to create or modify users.

Vulnerabilities in WordPress plugins remain one of the key vectors for compromising sites on this platform. Previously, we wrote about a critical RCE vulnerability in Forminator Forms and about an attack via forced theme installation. The Elementor case demonstrates how a single plugin module that incorrectly handles request validation can put an entire site at risk. Administrators of WordPress sites using Elementor should update the plugin to version 4.3.2 and audit administrator accounts — right now, without waiting for scheduled maintenance.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.