
Elementor CSRF Flaw Lets Attackers Take Over WordPress Sites via One Link
A high-severity CSRF vulnerability in Elementor versions 4.3.0 and 4.3.1 carries a CVSS score of 8.8 and lets an unauthenticated attacker create a rogue administrator account when a logged-in admin opens a crafted link.
The Elementor Website Builder plugin for WordPress contains a high-severity cross-site request forgery (CSRF) flaw that lets an unauthenticated attacker create rogue administrator accounts and take control of a site. The vulnerability, detailed by the WordPress security company Patchstack, has a CVSS score of 8.8 out of 10 and has not yet been assigned a CVE identifier.
Only versions 4.3.0 and 4.3.1 are affected. Elementor is active on more than 10 million WordPress sites, and statistics from WordPress.org show that the two impacted releases alone are installed on over 2 million sites.
How the protection is bypassed
According to Patchstack, the problem lies in the plugin's Editor Events module. That module skips CSRF protection for cookie-authenticated REST API requests whenever the literal string "elementor/v1/events/" appears anywhere in the request URI. Because the URI includes the query string, and the query string is written by whoever composes the link, any REST request can opt itself out of that protection by appending a harmless-looking parameter.
Since the check matches anywhere in the address, the bypass covers the entire REST API surface of a site: WordPress core routes as well as the routes registered by every other installed plugin.
One link, one new administrator
"One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform," Patchstack said. "On a stock installation, an administrator clicking the link creates a second administrator account for the attacker."
The company said the attack needs none of the usual prerequisites: no JavaScript, no submitted form and no page under the threat actor's control. The link can be a plain anchor tag inside an email, a chat message or a comment. On a standard install, a request to the /wp-json/wp/v2/users endpoint with the administrator role selected is enough to create the second admin account.
Fixed in version 4.3.2
The issue was addressed in Elementor 4.3.2, released earlier this week following responsible disclosure. Releases before 4.3.0 do not ship the Editor Events proxy, so they are not affected. A researcher known by the alias "Saggre" is credited with discovering and reporting the bug. Users of the plugin are advised to apply the latest update as soon as possible.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.