Elementor WordPress flaw lets attackers create admin accounts

Refract AI Intelligence Digest

BLUF

Unauthenticated attackers can gain full administrative control of WordPress sites via a CSRF flaw in Elementor.

NEWS

Security researchers identified a cross-site request forgery vulnerability in the Elementor plugin that bypasses authentication mechanisms. This exploit enables threat actors to silently create new administrator users on vulnerable installations without needing login credentials.

Why I Care

This affects any WordPress site using the vulnerable Elementor version, posing a critical risk of data theft, site defacement, or malware injection. The stakes are high because the attack requires no prior access or user interaction beyond visiting a malicious page.

Next Steps

WordPress administrators must update the Elementor plugin to the latest patched version immediately. If patching is not possible, disable the plugin and monitor logs for unauthorized account creation until a fix is applied.

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.