As reported by BleepingComputer, a cross-site request forgery (CSRF) vulnerability in the Elementor Website Builder plugin for WordPress could allow unauthenticated attackers to create administrator accounts via a single-click attack against a logged-in admin. The flaw affects versions 4.3.0 and 4.3.1 — covering an estimated 2 million of the plugin's 10 million active installations — and was patched in version 4.3.2 released September 24, 2026.
Vulnerability Details
| Field | Detail |
|---|---|
| Plugin | Elementor Website Builder for WordPress |
| Affected Versions | 4.3.0, 4.3.1 |
| Patched Version | 4.3.2 (released Sept 24, 2026) |
| CVE Identifier | Not yet assigned at time of reporting |
| Severity | High (admin account creation via CSRF on unauthenticated attacker side) |
| Root Cause | Editor Events module checks raw request URI for elementor/v1/events/ and bypasses WordPress REST nonce validation |
| Exploitation | No active exploitation reported yet; PoC path viable via one-click link |
| Reporter | Patchstack (researcher "Saggre"), disclosed Sept 22, 2026 |
Why This Matters Beyond the Headline
The technical detail that elevates this flaw above a routine CSRF is the nonce bypass mechanism. Elementor's Editor Events module inspects the raw request URI for a specific path string and, upon finding it, skips WordPress's standard REST API nonce validation. Because the URI also carries attacker-controlled query parameters, an adversary can append the magic path string to requests targeting other REST endpoints — effectively forging authenticated requests that execute with the victim's privileges.
This is not a classic CSRF requiring a form submission or JavaScript execution. A bare link — delivered by email, chat, or even a WordPress comment — is sufficient. That dramatically lowers the attacker's delivery cost and evades many traditional CSRF mitigations that rely on content-type or header checks.
For defenders, the implications extend beyond Elementor itself. The pattern of URI substring matching as an authentication bypass is a recurring anti-pattern in WordPress plugin code. Security teams managing WordPress estates should audit custom and third-party plugins for similar logic where path-string presence is used to short-circuit nonce checks.
Who Is Most Exposed
Shield53 Recommendations
Immediate Actions
- Patch now: Upgrade Elementor to version 4.3.2 immediately. Verify auto-updates did not silently fail on staging or production.
- Audit admin accounts: Review all administrator-level users for unexpected or recently created accounts. Remove any that cannot be attributed to legitimate activity.
- Check access logs: Look for requests to
/wp-json/elementor/v1/events/containing unusual query parameters or chained endpoint paths — indicators of exploitation attempts. - Restrict REST API surface: Where feasible, disable or gate unused WordPress REST API endpoints for unauthenticated users via
rest_authentication_errorsfilters or WAF rules. - Harden admin sessions: Enforce separate browser profiles or dedicated admin machines so that clicking arbitrary links does not occur within an authenticated WordPress session context.
Broader Hardening
- Deploy a WAF rule blocking requests where the
elementor/v1/events/string appears in query parameters rather than the legitimate URI path — a temporary mitigation for sites that cannot immediately patch. - Implement content security policy headers and
SameSite=Strictcookies where the WordPress configuration supports it to reduce CSRF delivery vectors. - For multi-site portfolios, use a patch management platform with version inventory to confirm no site remains on 4.3.0 or 4.3.1.
- Review Patchstack's original advisory for the full technical write-up and detection guidance.
Given Elementor's enormous install base and the simplicity of the attack vector, Shield53 assesses that opportunistic exploitation is likely within days of public disclosure. Organizations should treat this as a high-priority patch — not a routine update — and validate remediation across their entire WordPress footprint.