Patchstack disclosed a cross-site request forgery flaw in the Elementor Website Builder plugin, affecting versions 4.3.0 and 4.3.1, used on up to 2 million WordPress sites. The bug let attackers trick a logged-in administrator into clicking a malicious link that silently created a new admin account under attacker control. Elementor patched the issue in version 4.3.2, released two days after Patchstack's report.
bleepingcomputer.com
· 2026-09-25
Researcher Paulos Yibelo of pwn.ai disclosed a WordPress Core vulnerability, called Click2Shell, that chains a cross-site request forgery bug with the theme Customizer preview to achieve remote PHP execution. The flaw lets an attacker trick a logged-in administrator into visiting a malicious link, silently installing a theme from the WordPress.org catalog and running arbitrary PHP through the Customizer preview even before activation. WordPress fixed the issue in version 7.1.1 after it was reported in late August.
bleepingcomputer.com
· 2026-09-21