Download Privacy Needle App

Type to search

Cybersecurity

Elementor WordPress Plugin Flaw Allows Unauthorised Admin Account Creation

Share

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow unauthenticated attackers to create administrator accounts, potentially leading to full website takeover.

The flaw impacts versions 4.3.0 and 4.3.1 of the popular website builder. Security firm Patchstack reported the issue after it was discovered by researcher “Saggre”.

Elementor is a widely used drag-and-drop interface for WordPress, active on approximately 10 million websites. Statistics from WordPress.org suggest that the two vulnerable versions are in use by up to 2 million sites.

Technical Details of the CSRF Vulnerability

The vulnerability stems from Elementor’s Editor Events module. According to Patchstack’s analysis, the module checks the raw request URI for a specific path, elementor/v1/events/, and subsequently bypasses WordPress’s REST nonce validation when that string is detected.

Because the URI can contain attacker-controlled query parameters, a threat actor can append the target path to requests aimed at other REST endpoints. By tricking a logged-in administrator into opening a malicious link via email, chat, or a site comment, the attacker can force the victim’s authenticated session to perform administrative actions.

This “one-click” attack method does not require JavaScript, a specifically crafted webpage, or a submitted form. Once the link is clicked, the attacker can execute the REST API action required to create a new administrator account under their own control.

Remediation and Updates

Elementor has released a security patch in version 4.3.2, which prevents attackers from triggering the bypass through the query string.

Administrators using the Elementor plugin are urged to upgrade to version 4.3.2 as soon as possible to mitigate the risk of unauthorised access.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.