Elementor patches CSRF bug enabling WordPress administrator takeover

Elementor has released version 4.3.2 to fix a high-severity cross-site request forgery vulnerability in its Website Builder plugin for WordPress. The flaw affects Elementor 4.3.0 and 4.3.1 and could allow an unauthenticated attacker to create a rogue administrator account if a logged-in WordPress administrator opens a crafted link.
The issue has a CVSS score of 8.8 and has not yet received a CVE identifier. Elementor is active on more than 10 million WordPress sites; WordPress.org statistics indicate that the two affected versions alone have been installed on more than 2 million sites.
Crafted link could trigger privileged REST API actions
Patchstack, which disclosed the vulnerability after responsible reporting, said a single link could make an authenticated WordPress user perform any REST API action their account was permitted to carry out. On a standard installation, a link opened by an administrator could create a second administrator account controlled by the attacker.
The attack does not require JavaScript, a form submission or a page hosted by the attacker. A plain link placed in an email, chat message or comment can be sufficient to initiate the request when opened by an authenticated user.
URI check bypassed CSRF protection
Patchstack traced the problem to Elementor’s Editor Events module. The module skipped CSRF protection for cookie-authenticated REST API requests whenever the literal string elementor/v1/events/ appeared anywhere in the request URI.
Because a request URI includes its query string, an attacker could add that string as an apparently harmless parameter to cause a REST request to bypass the protection. Patchstack said the effect extended across the site’s REST API surface, including WordPress core endpoints and routes supplied by other installed plugins.
An attacker could use the WordPress /wp/v2/users endpoint in such a request to create an account with the administrator role. The flaw is not present in Elementor releases before 4.3.0 because they do not include the Editor Events proxy.
Update affected installations
Security researcher Saggre discovered and reported the issue. Organisations running Elementor 4.3.0 or 4.3.1 should update to 4.3.2 as soon as possible and prioritise sites where administrators regularly open links received through email, messaging platforms or comments.
The incident reinforces that plugin updates should be treated as an operational control: teams should maintain an inventory of WordPress extensions and versions so they can quickly identify affected sites, apply vendor fixes and reduce the exposure of privileged accounts.

