Elementor WordPress flaw lets attackers create admin accounts
BLUF
Unauthenticated attackers can gain full administrative control of WordPress sites via a CSRF flaw in Elementor.
NEWS
Security researchers identified a cross-site request forgery vulnerability in the Elementor plugin that bypasses authentication mechanisms. This exploit enables threat actors to silently create new administrator users on vulnerable installations without needing login credentials.
Why I Care
This affects any WordPress site using the vulnerable Elementor version, posing a critical risk of data theft, site defacement, or malware injection. The stakes are high because the attack requires no prior access or user interaction beyond visiting a malicious page.
Next Steps
WordPress administrators must update the Elementor plugin to the latest patched version immediately. If patching is not possible, disable the plugin and monitor logs for unauthorized account creation until a fix is applied.
Source: BleepingComputer ·