Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Microsoft’s new Copilot app puts everything in one place – but the price is ‘evolving’

    September 25, 2026

    PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    September 25, 2026

    Former Hack VC Partner and Dystopia Labs Founder Dies at 37

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Microsoft’s new Copilot app puts everything in one place – but the price is ‘evolving’
    • PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
    • Former Hack VC Partner and Dystopia Labs Founder Dies at 37
    • 2026-2027 DWU Middle School Design Challenge
    • To tackle environmental crime, track profits through the whole supply chain (commentary)
    • Despite $18 million push, DeSantis-backed property tax amendment faces uphill battle • OpenSecrets
    • The Twilight of the Francis Fukuyama Era
    • Republican Ad Attacks Cooper with Misleading Claim About Rape Kits
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Elementor WordPress flaw lets attackers create admin accounts

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts.

    Threat actors can exploit the flaw by tricking a logged-in administrator into opening a malicious link, causing the victim’s authenticated session to perform a REST API action permitted by their account.

    On default installations, the result is the creation of an administrator account under the control of the attacker.

    The Elementor Website Builder is a popular WordPress plugin active on 10 million websites that lets users create websites using a drag-and-drop interface.

    The CSRF flaw has yet to receive an identifier and impacts only versions 4.3.0 and 4.3.1. According to statistics from WordPress.org, the two versions are used by up to 2 million sites.

    Security firm Patchstack reported the vulnerability to the Elementor team on September 22 after receiving it from bug hunter “Saggre.” Elementor released a fix two days later, in version 4.3.2 of the plugin.

    According to Patchstack’s analysis, the CSRF flaw is caused by Elementor’s Editor Events module checking the raw request URI for the elementor/v1/events/ path and bypassing WordPress’s REST nonce validation when that string is present.

    Because the URI also contains attacker-controlled query parameters, attackers can append the path to requests targeting other REST endpoints and trick logged-in users into executing them with their existing privileges.

    Patchstack says the flaw can be abused in one-click attacks against a logged-in administrator to create a new attacker-controlled admin account.

    “One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform,” Patchstack explains.

    The security firm says that the attack does not require JavaScript, an attacker-controlled webpage, or a submitted form, and the link can be delivered to the target via email, a chat message, or a comment on the site.

    Elementor releases before 4.3.0 do not contain the affected Editor Events proxy, but those older versions are vulnerable to other flaws, some of which are already actively exploited.

    Users of the plugin are recommended to upgrade to Elementor version 4.3.2 as soon as possible, which prevents attackers from triggering the bypass through the query string.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Accounts Admin Attackers create Elementor Flaw lets WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

    Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

    OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

    Whitehat Rescues 3,832 NFTs Amid Suspected Magic Eden Flaw

    Fixing Flock: The controls needed now that misuse patterns are clear

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Microsoft’s new Copilot app puts everything in one place – but the price is ‘evolving’

    September 25, 2026

    PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    September 25, 2026

    Former Hack VC Partner and Dystopia Labs Founder Dies at 37

    September 25, 2026

    2026-2027 DWU Middle School Design Challenge

    September 25, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Microsoft’s new Copilot app puts everything in one place – but the price is ‘evolving’

    September 25, 2026

    PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    September 25, 2026

    Former Hack VC Partner and Dystopia Labs Founder Dies at 37

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.