Vulnerabilities · 2h ago
BleepingComputer reports a cross-site request forgery flaw in the Elementor WordPress plugin that can let an unauthenticated attacker create administrator accounts. The issue matters because the result is not a one-time page change: it hands the attacker persistent full-site control.
The trick is to abuse a logged-in site admin’s browser so it sends a request Elementor accepts as legitimate. That request creates a new admin account for the attacker, so they no longer need the victim’s password or browser session to get back in.
For WordPress sites that rely on third-party plugins and browser-based administration, the exposure sits in account creation and not just login security. If an attacker can add their own admin, password rotation on the original account does not remove the foothold they created.
2 sources covering this story
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Elementor 4.3.0 and 4.3.1 contain a CSRF flaw that can create an admin account when a logged-in administrator opens a crafted link.
Elementor WordPress flaw lets attackers create admin accounts
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts.
Part of the PlainSec briefing for 2026-09-26