Elementor CSRF Flaw Lets Attackers Create Admins
🔒 A high-severity CSRF vulnerability in the Elementor Website Builder (versions 4.3.0 and 4.3.1) allows an unauthenticated attacker to coerce logged-in users into performing REST API actions, including creating rogue administrator accounts. Patchstack reported the issue, which affects over 2 million installations of those versions and has a CVSS score of 8.8. The flaw stems from the Editor Events module skipping CSRF checks when "elementor/v1/events/" appears in the request URI. Elementor addressed the bug in version 4.3.2 following disclosure by researcher "Saggre," and users are urged to update immediately.
