Elementor CSRF Flaw Exposes WordPress Sites to Link-Based Takeover
Elementor fixed a CSRF flaw in versions 4.3.0 and 4.3.1 that could let attackers abuse a logged-in WordPress administrator’s browser to create rogue admin accounts.

The Hacker News detailed a high-severity flaw in Elementor’s WordPress website builder that could let an unauthenticated attacker take over a site after a logged-in administrator clicks a crafted link.
The weakness is a cross-site request forgery issue that has not yet received a CVE identifier.
It carries a CVSS score of 8.8 and affects Elementor versions 4.3.0 and 4.3.1, a narrow release window with a large footprint because the plugin is active on more than 10 million WordPress sites.
WordPress.org statistics put the two affected versions alone on more than 2 million installations.
That scale turns a link-based bug into an urgent patching problem for site operators, especially because the exploit path does not require an attacker to host a malicious page or rely on JavaScript.
Patchstack said a single link opened by an authenticated WordPress user can make that user perform any REST API action their account is allowed to perform.
On a standard installation, an administrator who clicks the link can end up creating a second administrator account controlled by the attacker.
The same security company said the attack can be delivered through a plain anchor tag in an email, chat message or comment.
The important condition is the victim’s logged-in browser session, not a submitted form or an attacker-controlled web page.
Elementor addressed the issue in version 4.3.2, released earlier this week after responsible disclosure.
A researcher using the alias “Saggre” was credited with finding and reporting the bug.
The vulnerable behavior sits in the Editor Events module.
When the literal string “elementor/v1/events/” appears anywhere in the request URI, the module skips CSRF protection for cookie-authenticated REST API requests.
Because the request URI includes the query string, a harmless-looking parameter added by the person composing the link can opt another REST request out of that protection, Patchstack added.
The bypass reaches beyond Elementor’s own functions.
It applies to the entire REST API surface of the site, including WordPress core routes and routes exposed by other installed plugins.
For administrators, the practical control is straightforward: sites still running Elementor 4.3.0 or 4.3.1 remain exposed until they move to 4.3.2 or later, and the risk is highest for users with accounts powerful enough to create or alter site administration settings.




















