Elementor bug let attackers create admin accounts on up to 2 million sites
A CSRF flaw in Elementor’s Editor Events module is patched in version 4.3.2, and users are urged to upgrade quickly.
Elementor fixed a cross-site request forgery flaw in plugin releases 4.3.0 and 4.3.1; up to 2 million sites run those versions. An attacker who gets a logged-in administrator to click a crafted link could add a rogue account with administrator rights. The mechanism involves Elementor’s Editor Events module treating a request URI containing elementor/v1/events/ as grounds to skip WordPress REST nonce validation. Elementor released version 4.3.2 as the remedy, and plugin users are urged to install it promptly.
Why it matters
This flaw matters because it turns a single click by a logged-in administrator into full site takeover, on potentially up to 2 million WordPress installations using the affected Elementor versions. With the Editor Events module skipping WordPress REST nonce checks for certain requests, attackers could quietly add their own admin accounts until site owners move to the fixed 4.3.2 release, making fast updates critical for anyone running vulnerable sites.
Signal or noise?
Does this story matter, or is it hype? Decide before you see what everyone else thinks.
Sources
- BleepingComputer