Elementor CSRF Flaw Lets Attackers Create Admins
🔒 A CSRF vulnerability in the Elementor WordPress plugin could let an unauthenticated attacker create administrator accounts by tricking a logged-in admin into opening a crafted link. The flaw affects versions 4.3.0 and 4.3.1, which are active on up to 2 million sites. Patchstack reported the issue to Elementor on September 22 and a fix was issued in version 4.3.2 two days later. Users are advised to update immediately to prevent one-click admin account creation attacks.