Elementor Website Builder versions 4.3.0 and 4.3.1 contain a cross-site request forgery (CSRF) flaw that can enable an unauthenticated attacker to create an administrator account on a WordPress site. Exploitation requires convincing a logged-in WordPress administrator to follow a malicious link, causing the victim’s authenticated session to submit a REST API account-creation request.
The issue stems from the Editor Events module bypassing WordPress REST nonce validation when a raw request URI includes elementor/v1/events/; attackers can append that path in query parameters to target other REST endpoints. Elementor fixed the vulnerability in version 4.3.2; organizations running the affected releases—potentially up to 2 million sites—should update immediately and review administrator accounts for unauthorized additions.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Elementor released version 4.3.2 to remediate the Editor Events nonce-validation bypass, preventing the bypass from being triggered through a query string. The vulnerable 4.3.0 and 4.3.1 releases may be deployed on up to 2 million sites.
Patchstack reported a cross-site request forgery vulnerability in Elementor Website Builder 4.3.0 and 4.3.1 to the Elementor team. The flaw could let attackers trick a logged-in WordPress administrator into creating an attacker-controlled administrator account.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.