Skip to content
Tech News
← Back to articles

Elementor plugin CSRF bug let attackers create WordPress admin accounts

read original get YubiKey 5C NFC Security Key → more articles
GoKawiil Brief

Patchstack disclosed a cross-site request forgery flaw in the Elementor Website Builder plugin, affecting versions 4.3.0 and 4.3.1, used on up to 2 million WordPress sites. The bug let attackers trick a logged-in administrator into clicking a malicious link that silently created a new admin account under attacker control. Elementor patched the issue in version 4.3.2, released two days after Patchstack's report.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The flaw shows how a single mishandled URI check can bypass WordPress's built-in nonce protections, exposing any REST API action tied to a logged-in user's privileges. Because exploitation required no JavaScript or fake webpage—just a clicked link sent via email or chat—it lowered the bar for full site takeover on millions of installs. This case underscores the risk that popular plugins with broad install bases pose a large attack surface even when the core WordPress platform itself is secure.

Key Takeaways
Worth a Look

YubiKey 5C NFC Security Key — With WordPress admin accounts being a prime target for attackers exploiting flaws like this Elementor CSRF bug, adding hardware-based two-factor authentication is a smart move for site administrators. A YubiKey lets you require physical confirmation before any sensitive login or account change, making it much harder for attackers to hijack admin sessions even if a CSRF exploit succeeds.

See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: bleepingcomputer.com, 2026-09-25

Published there as: “Elementor WordPress flaw lets attackers create admin accounts”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.