Tech News
← Home  ·  All topics

Elementor

2 GoKawiil briefs on this topic

Elementor plugin CSRF bug let attackers create WordPress admin accounts

Patchstack disclosed a cross-site request forgery flaw in the Elementor Website Builder plugin, affecting versions 4.3.0 and 4.3.1, used on up to 2 million WordPress sites. The bug let attackers trick a logged-in administrator into clicking a malicious link that silently created a new admin account under attacker control. Elementor patched the issue in version 4.3.2, released two days after Patchstack's report.

Attackers exploit patched Elementor Pro flaw to plant webshells on WordPress sites

Hackers are actively exploiting CVE-2026-32475, a critical vulnerability in Elementor Pro affecting version 4.2.1 and earlier, by abusing a file-upload validation flaw in the plugin's form widget to upload malicious PHP files and run commands on compromised servers. Elementor patched the bug on August 19 with version 4.2.2, but Wordfence says exploitation began the same day and has already blocked nearly 200,000 attack attempts.