As reported by BleepingComputer, a cross-site request forgery (CSRF) vulnerability in the Elementor Website Builder plugin for WordPress could allow unauthenticated attackers to create administrator accounts via a single-click attack against a logged-in admin. The flaw affects versions 4.3.0 and 4.3.1 — covering an estimated 2 million of the plugin's 10 million active installations — and was patched in version 4.3.2 released September 24, 2026.

Security Impact: As reported by BleepingComputer, a cross-site request forgery (CSRF) vulnerability in the Elementor Website Builder plugin for WordPress could allow unauthenticated attackers to create administrator accounts via a single-click attack against a logged-in admin.

Vulnerability Details

FieldDetail
PluginElementor Website Builder for WordPress
Affected Versions4.3.0, 4.3.1
Patched Version4.3.2 (released Sept 24, 2026)
CVE IdentifierNot yet assigned at time of reporting
SeverityHigh (admin account creation via CSRF on unauthenticated attacker side)
Root CauseEditor Events module checks raw request URI for elementor/v1/events/ and bypasses WordPress REST nonce validation
ExploitationNo active exploitation reported yet; PoC path viable via one-click link
ReporterPatchstack (researcher "Saggre"), disclosed Sept 22, 2026

Why This Matters Beyond the Headline

The technical detail that elevates this flaw above a routine CSRF is the nonce bypass mechanism. Elementor's Editor Events module inspects the raw request URI for a specific path string and, upon finding it, skips WordPress's standard REST API nonce validation. Because the URI also carries attacker-controlled query parameters, an adversary can append the magic path string to requests targeting other REST endpoints — effectively forging authenticated requests that execute with the victim's privileges.

This is not a classic CSRF requiring a form submission or JavaScript execution. A bare link — delivered by email, chat, or even a WordPress comment — is sufficient. That dramatically lowers the attacker's delivery cost and evades many traditional CSRF mitigations that rely on content-type or header checks.

For defenders, the implications extend beyond Elementor itself. The pattern of URI substring matching as an authentication bypass is a recurring anti-pattern in WordPress plugin code. Security teams managing WordPress estates should audit custom and third-party plugins for similar logic where path-string presence is used to short-circuit nonce checks.

Who Is Most Exposed

Why This Matters Beyond the Headline
Content-heavy publishers and SMBs running Elementor on default configurations — the attack creates an admin on default installs.
Agencies managing multiple client sites where patch latency is common across a fleet.
Sites with open comment sections, since the malicious link can be planted in a comment visible to logged-in editors or admins.
Environments where admins click links from email or Slack while authenticated to the WordPress backend — the realistic everyday scenario.

Shield53 Recommendations

Immediate Actions

  • Patch now: Upgrade Elementor to version 4.3.2 immediately. Verify auto-updates did not silently fail on staging or production.
  • Audit admin accounts: Review all administrator-level users for unexpected or recently created accounts. Remove any that cannot be attributed to legitimate activity.
  • Check access logs: Look for requests to /wp-json/elementor/v1/events/ containing unusual query parameters or chained endpoint paths — indicators of exploitation attempts.
  • Restrict REST API surface: Where feasible, disable or gate unused WordPress REST API endpoints for unauthenticated users via rest_authentication_errors filters or WAF rules.
  • Harden admin sessions: Enforce separate browser profiles or dedicated admin machines so that clicking arbitrary links does not occur within an authenticated WordPress session context.

Broader Hardening

  • Deploy a WAF rule blocking requests where the elementor/v1/events/ string appears in query parameters rather than the legitimate URI path — a temporary mitigation for sites that cannot immediately patch.
  • Implement content security policy headers and SameSite=Strict cookies where the WordPress configuration supports it to reduce CSRF delivery vectors.
  • For multi-site portfolios, use a patch management platform with version inventory to confirm no site remains on 4.3.0 or 4.3.1.
  • Review Patchstack's original advisory for the full technical write-up and detection guidance.

Given Elementor's enormous install base and the simplicity of the attack vector, Shield53 assesses that opportunistic exploitation is likely within days of public disclosure. Organizations should treat this as a high-priority patch — not a routine update — and validate remediation across their entire WordPress footprint.