A severe cross-site request forgery (CSRF) vulnerability in Elementor, the website builder plugin used on more than 10 million WordPress sites, allows attackers to hand themselves a fully privileged administrator account — no password, no exploit chain, just one click from a logged-in site admin.
What happened
The flaw, scored 8.8 out of 10 on the CVSS scale and still awaiting a CVE identifier, sits in Elementor's Editor Events module. That component is supposed to check a security token (nonce) before acting on any REST API request. Researchers found that the check silently skips itself whenever the request's full URL — including its query string — contains the text "elementor/v1/events/" anywhere at all.
Because attackers control the query string of any link they send, they can tack that string onto a request aimed at a completely different part of WordPress's REST API and slip past the CSRF protection for the entire site — not just Elementor's own features, but core WordPress endpoints and every other installed plugin's API routes too.
In practice, that means a booby-trapped link — sent as a plain anchor in an email, a chat message, or a blog comment, with no JavaScript or extra trickery required — can silently submit a request that creates a brand-new administrator account the moment a logged-in admin opens it. From there, the attacker owns the site.
Only Elementor versions 4.3.0 and 4.3.1 are affected; earlier releases never shipped the vulnerable Editor Events proxy. Even limited to those two versions, tracking data shows roughly two million active installs were exposed before a fix shipped this week in version 4.3.2.
Why it matters
CSRF bugs are often dismissed as low-impact because they need a victim to take some action. This one erases that excuse: the "action" is a single click on what looks like an ordinary link, the attack works against the REST API surface of the entire site rather than one form, and the payoff is a brand-new admin account — the highest privilege WordPress has. For agencies and businesses running Elementor on client sites, that's a direct path from "someone clicked a bad link" to full site takeover, malware injection, or data theft.
What to do
- Update Elementor to version 4.3.2 or later immediately on every site where it's installed — this is the only complete fix.
- If you can't patch right away, restrict which accounts have publisher/administrator roles and be cautious about links shared in email or chat while the site is unpatched.
- Audit the WordPress user list for any administrator accounts you don't recognize, especially ones created in the last week.
- Consider a web application firewall (WAF) rule that blocks REST API requests carrying unexpected query-string patterns as a stopgap while patching rolls out across your sites.
- Keep automatic plugin updates enabled where your workflow allows it — CSRF and authorization bugs in widely used plugins like this one are prime targets for opportunistic attackers within days of disclosure.
