Tech News
← Home  ·  All topics

Csrf Vulnerability

2 GoKawiil briefs on this topic

Elementor plugin CSRF bug let attackers create WordPress admin accounts

Patchstack disclosed a cross-site request forgery flaw in the Elementor Website Builder plugin, affecting versions 4.3.0 and 4.3.1, used on up to 2 million WordPress sites. The bug let attackers trick a logged-in administrator into clicking a malicious link that silently created a new admin account under attacker control. Elementor patched the issue in version 4.3.2, released two days after Patchstack's report.

WordPress patches 'Click2Shell' CSRF flaw enabling remote code execution

Researcher Paulos Yibelo of pwn.ai disclosed a WordPress Core vulnerability, called Click2Shell, that chains a cross-site request forgery bug with the theme Customizer preview to achieve remote PHP execution. The flaw lets an attacker trick a logged-in administrator into visiting a malicious link, silently installing a theme from the WordPress.org catalog and running arbitrary PHP through the Customizer preview even before activation. WordPress fixed the issue in version 7.1.1 after it was reported in late August.