A critical cross-site request forgery (CSRF) vulnerability in the Elementor Website Builder plugin for WordPress (versions 4.3.1 and earlier) was disclosed on September 25, 2026, allowing unauthenticated attackers to create administrator accounts. The vulnerability was patched in an updated version, and administrators were urged to update immediately.
5 reports · 4 independentother · tech
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. https://www. bleepingcomputer.com/news/secu rity/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/