{
  "id": 9892899,
  "title": "Elementor 4.3.0 and 4.3.1: CSRF Enables Administrator Account Creation via a Flawed REST Route Check",
  "url": "https://urgent.news/2026/09/26/elementor-4-3-0-and-4-3-1-csrf-enables-administrator-account-creation",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-26T02:29:01.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/elementor-430-and-431-csrf-enables-administrator-account-creation-via-a-flawed-rest-route-check-4m57"
  },
  "original_language": "en",
  "account": "Elementor 4.3.0 and 4.3.1, used by over two million WordPress sites, contain a Cross-Site Request Forgery (CSRF) vulnerability. This flaw allows an attacker to create a new administrator account if an administrator user unknowingly opens a specially crafted URL while logged into WordPress. Elementor's Editor Events feature partially matches REST API routes, bypassing the required nonce validation, which would otherwise prevent such unauthorized actions. Once the new administrator account is created, the attacker can exploit the elevated privileges for further malicious activities, such as modifying site content or escalating the breach. Updating Elementor to version 4.3.2 or later is crucial to mitigate this risk.",
  "summary": "1. Basic Information Title: Cross-Site Request Forgery in Elementor Plugin Affecting 2 Million+ Sites Source: Patchstack Published: September 25, 2026 Updated: N/A Severity: critical Severity Basis: When an authenticated administrator opens a crafted link, an attacker can create an administrator account on sites running Elementor 4.3.0 or 4.3.1 with Editor Events enabled. Patchstack rates this as…",
  "key_points": [
    "CSRF vulnerability in Elementor versions 4.3.0 and 4.3.1",
    "Attackers can create administrator accounts via crafted URLs",
    "Updating to version 4.3.2 or later mitigates the risk"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}