Vulnerability Management

Elementor plugin vulnerability allows admin account creation

(Credit: Bilal Ulker – stock.adobe.com)

As reported by Bleeping Computer, a cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts on affected websites.

Threat actors can exploit this flaw by tricking a logged-in administrator into clicking a malicious link. This action leverages the administrator's authenticated session to perform a REST API action, specifically creating a new administrator account under the attacker's control. The vulnerability, identified in Elementor versions 4.3.0 and 4.3.1, impacts up to 2 million websites. The flaw stems from the Editor Events module bypassing WordPress's REST nonce validation under certain conditions.

Security firm Patchstack reported the vulnerability, and Elementor released version 4.3.2 to address the issue. The attack requires no JavaScript or complex setup, allowing delivery via email or chat messages. Users are strongly advised to update to version 4.3.2 immediately to prevent unauthorized account creation.

Source: Bleeping Computer

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds