Critical Elementor Plugin Flaw Exposes 2 Million WordPress Sites to Admin Account Hijacks
A high-severity cross-site request forgery (CSRF) vulnerability in the **Elementor Website Builder** WordPress plugin has been disclosed, potentially allowing unauthenticated attackers to create rogue administrator accounts. Affecting over 2 million sites running specific versions, the flaw carries a CVSS score of 8.8 and can be exploited with a single crafted link.

Details have emerged regarding a critical security vulnerability within the **Elementor Website Builder** plugin for **WordPress**. This flaw could enable an unauthenticated attacker to create illicit administrator accounts, thereby seizing control of affected websites.
### High-Severity CSRF Vulnerability
The cross-site request forgery (CSRF) vulnerability, yet to be assigned a **CVE** identifier, has a significant **CVSS** score of 8.8 out of 10.0. It specifically impacts **Elementor** plugin versions 4.3.0 and 4.3.1. These versions are actively installed on over 2 million **WordPress** sites globally, out of the more than 10 million total installations of the plugin.
Security firm **Patchstack** highlighted the simplicity of the attack: "One link, opened by a logged-in **WordPress** user, makes that user carry out any **REST API** action their account is permitted to perform." For a default **WordPress** installation, an administrator merely clicking a malicious link could inadvertently create a new administrator account for the attacker.
### Effortless Exploitation
What makes this vulnerability particularly dangerous is the minimal prerequisites for exploitation. The attack does not rely on **JavaScript**, submitted forms, or a web page controlled by the threat actor. A simple anchor tag embedded in an email, chat message, or comment is sufficient to trigger the exploit.
### The Root Cause and Patch
The vulnerability stems from the **Editor Events** module in **Elementor**, which bypasses **CSRF** protection for cookie-authenticated **REST API** requests. This bypass occurs whenever the literal string "elementor/v1/events/" is present anywhere in the request URI. **Patchstack** explained that since the request URI includes the query string, an attacker can append a seemingly harmless parameter to opt out of the **CSRF** protection.
This bypass extends to the entire **REST API** surface of a site, encompassing **WordPress** core routes and those of other installed plugins. An attacker could exploit this loophole to create an administrator account via the `/wp/v2/users` endpoint using a crafted request similar to this example:
### Immediate Action Required
Following responsible disclosure, **Elementor** addressed the issue in **version 4.3.2**, released earlier this week. Security researcher "**Saggre**" is credited with discovering and reporting the bug. Versions of **Elementor** prior to 4.3.0 are not affected as they do not include the **Editor Events** proxy.
All users of the **Elementor** plugin running affected versions (4.3.0 and 4.3.1) are strongly advised to update to **version 4.3.2** immediately to mitigate this significant security risk.