SendTech Times
News
MARKET SIGNAL:

Elementor CSRF Flaw Exposes WordPress Sites to Link-Based Takeover

Newsroom brief

Elementor fixed a CSRF flaw in versions 4.3.0 and 4.3.1 that could let attackers abuse a logged-in WordPress administrator’s browser to create rogue admin accounts.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: The Hacker News
Elementor CSRF Flaw Exposes WordPress Sites to Link-Based Takeover
Image source: The Hacker News

The Hacker News detailed a high-severity flaw in Elementor’s WordPress website builder that could let an unauthenticated attacker take over a site after a logged-in administrator clicks a crafted link.

The weakness is a cross-site request forgery issue that has not yet received a CVE identifier.

It carries a CVSS score of 8.8 and affects Elementor versions 4.3.0 and 4.3.1, a narrow release window with a large footprint because the plugin is active on more than 10 million WordPress sites.

WordPress.org statistics put the two affected versions alone on more than 2 million installations.

That scale turns a link-based bug into an urgent patching problem for site operators, especially because the exploit path does not require an attacker to host a malicious page or rely on JavaScript.

Patchstack said a single link opened by an authenticated WordPress user can make that user perform any REST API action their account is allowed to perform.

On a standard installation, an administrator who clicks the link can end up creating a second administrator account controlled by the attacker.

The same security company said the attack can be delivered through a plain anchor tag in an email, chat message or comment.

The important condition is the victim’s logged-in browser session, not a submitted form or an attacker-controlled web page.

Elementor addressed the issue in version 4.3.2, released earlier this week after responsible disclosure.

A researcher using the alias “Saggre” was credited with finding and reporting the bug.

The vulnerable behavior sits in the Editor Events module.

When the literal string “elementor/v1/events/” appears anywhere in the request URI, the module skips CSRF protection for cookie-authenticated REST API requests.

Because the request URI includes the query string, a harmless-looking parameter added by the person composing the link can opt another REST request out of that protection, Patchstack added.

The bypass reaches beyond Elementor’s own functions.

It applies to the entire REST API surface of the site, including WordPress core routes and routes exposed by other installed plugins.

For administrators, the practical control is straightforward: sites still running Elementor 4.3.0 or 4.3.1 remain exposed until they move to 4.3.2 or later, and the risk is highest for users with accounts powerful enough to create or alter site administration settings.

Share this article
inXf

Related articles

More
MCP Python SDK Fix Closes OAuth Credential Redirect Flaw
Cybersecurity

MCP Python SDK Fix Closes OAuth Credential Redirect Flaw

The official MCP Python SDK has fixed a flaw that could let a malicious server redirect OAuth secrets, authorization codes and PKCE proof keys during AI tool sign-ins.

Calix Router Flaw Exposes Home Devices To Public Internet
Cybersecurity

Calix Router Flaw Exposes Home Devices To Public Internet

An unpatched Calix GS7 XGS router flaw lets unauthenticated attackers create port-forwarding rules that can expose devices inside broadband customers' home networks.

CISA Adds LoadMaster Flaw After 792 Exploit Attempts
Cybersecurity

CISA Adds LoadMaster Flaw After 792 Exploit Attempts

The Hacker News covered CISA's KEV listing for CVE-2026-8037 after KEVIntel telemetry counted 792 exploitation attempts against Progress Kemp LoadMaster over 41 days.

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk
Cybersecurity

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk

SecurityWeek reported that OpenAI fixed the AgentForger flaw in ChatGPT Workspace Agents after Zenity Labs showed how a phishing link could create a hidden autonomous agent with access to already-authorised connectors.

Rails Fixes Critical Active Storage File-Read Vulnerability
Cybersecurity

Rails Fixes Critical Active Storage File-Read Vulnerability

BleepingComputer reported that Rails maintainers patched CVE-2026-66066, a critical Active Storage flaw tied to libvips image processing and possible file exposure in vulnerable applications.

MovieReaper Malware Spreads Through Compromised Torrent Repository
Cybersecurity

MovieReaper Malware Spreads Through Compromised Torrent Repository

Kaspersky traced MovieReaper infections to a compromised public torrent-file repository that let attackers distribute malicious movie-themed downloads across multiple tracker sites.

Cloudflare Precursor Scores Browser Sessions As Bot Traffic Hits 57 Percent
Cybersecurity

Cloudflare Precursor Scores Browser Sessions As Bot Traffic Hits 57 Percent

Cloudflare made Precursor generally available to score visitor behaviour across full browser sessions rather than one arrival check. The public record still lacks pricing, customer adoption figures and customer false-positive rates for the session-scoring product.

ClickFix Attack Uses Browser Cache To Hide Malware Payload
Cybersecurity

ClickFix Attack Uses Browser Cache To Hide Malware Payload

Microsoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.

Keep Reading

More Stories

Latest
The Loop X Opens Flagship Store Built Around Hands-On Device TestingDevices & Consumer TechOct 6, 2026The Loop X Opens Flagship Store Built Around Hands-On Device TestingThe Loop X opened its first flagship store at SM North EDSA The Annex, combining phones, laptops, wearables, accessories, experience zones and an in-store matcha bar.Ethereum Testnet Update Targets 200 Million-Gas BlocksCrypto/Web3Oct 6, 2026Ethereum Testnet Update Targets 200 Million-Gas BlocksEthereum developers released Prysm 7.2.1 so the Sepolia trial of Glamsterdam can test 200 million-gas blocks, more than three times the prior 60 million setting, before any main-network change.Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.