A serious CSRF (Cross-Site Request Forgery) vulnerability has been identified in the popular Elementor Website Builder plugin for WordPress , allowing unauthorized attackers to create malicious administrator accounts and take full control of websites. The vulnerability affects only versions 4.3.0 and 4.3.1 of the plugin, which are installed on more than 2 million websites worldwide. The scope of the threat is particularly concerning, given that Elementor is active on over 10 million WordPress sites overall.

The vulnerability has been rated with a CVSS score of 8.8 out of 10. While an official CVE number has not yet been assigned , security firm Patchstack has published detailed technical details on how the attack works. According to the findings, an attacker only needs to convince a logged-in user WordPress to click on a properly crafted link — no other prerequisites.
The particularly dangerous element of this vulnerability is its simplicity. It does not require JavaScript, form submission, or a website under the attacker's control. The malicious link can even be a simple anchor tag embedded in an email, chat message, or comment on a website. If the recipient is an administrator of the WordPress site and clicks, the attacker automatically gains administrator privileges.
See also: WordPress: Malicious version of Admin Menu Editor Pro installed on 1,500 sites
How the Elementor CSRF vulnerability works technically
The root of the problem is found in the Editor Events module of Elementor. Specifically, this module bypasses CSRF for REST API requests that use cookie authenticationwhenever the string “elementor/v1/events/” appears anywhere in the request URI. This creates a critical security hole.
Because the request URI includes the query string , and the query string is defined by the linker, any REST API request can be "excluded" from this protection by simply adding an innocent parameter. This bypass applies to the entire REST API surface of the site, including the basic WordPress core paths as well as the paths of any other plugins that are installed.
An attacker can exploit this vulnerability to create an administrator account via the /wp/v2/users. In practice, this means that if an administrator clicks on the malicious link, a second administrator account is automatically created for the attacker — without any visible indication that anything went wrong. The attacker thus gains full access to the website's backend.
It is important to note that versions of Elementor prior to 4.3.0 do not include the Editor Events proxy and are therefore not affected by this vulnerability. The issue was specifically introduced with versions 4.3.0 and 4.3.1.
Impact of Elementor CSRF vulnerability and remediation actions
The security researcher using the pseudonym “Saggre” discovered and responsibly reported the vulnerability to the authorities. Following the responsible disclosure process , the issue was addressed with the release of Elementor version 4.3.2 last week . All users of the plugin are urged to apply the update immediately.
See also: King Addons for Elementor: Critical vulnerability in WordPress plugin
The impact of a successful exploitation of this vulnerability could be devastating. An attacker with administrative privileges could install malicious plugins, modify content, steal user data, install backdoors for future access, or even use the site to distribute malware. On commercial sites, the damage could extend to financial losses and loss of customer trust.

Patchstack , a WordPress security firm, said the attack is particularly insidious because it leaves no visible traces at the time of execution. The user who clicks on the link has no idea that any malicious action has been taken. This makes detecting the attack extremely difficult without proper monitoring tools .
Practical tips for protecting against Elementor CSRF vulnerabilities
The most critical action for any WordPress site administrator using Elementor is to immediately upgrade to version 4.3.2 or later. The update can be done directly from the WordPress admin panel via the Plugins → Updates section. There is no reason to delay, as the vulnerability is actively exploitable.
See also: WordPress: Critical vulnerability in Elementor Pro is used in cyberattacks
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In addition to reporting the issue immediately, administrators should check admin accounts site's for any suspicious or unknown accounts that may have been created without their knowledge. If a suspicious account is found, it should be deleted immediately and all passwords changed. It is also recommended to check access logs for suspicious requests to the /wp/v2/users endpoint.
For additional protection, administrators can use solutions like Patchstack or other WordPress security plugins that provide virtual patchingandreal-time monitoring. Additionally, implementing the principle of least privilege — that is, avoiding using an administrator account for day-to-day tasks — significantly reduces the risk of CSRF attacks.
Source: The Hacker News
