Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-28 · updated: 2026-09-28 · tags: [incident, global] · confidence: high · severity: medium · affected_sectors: [global] · au_impact: true

A cross-site request forgery flaw in the Elementor Website Builder plugin allows an unauthenticated attacker to create an administrator account, affecting the plugin versions 4.3.0 and 4.3.1 in use on up to two million WordPress sites out of the roughly 10 million that run the plugin. Patchstack, which received the report from researcher "Saggre" on 22 September, found the cause in Elementor's Editor Events module: it checks the raw request URI for the elementor/v1/events/ path and bypasses WordPress's REST nonce validation whenever that string is present. Because the URI also carries attacker-controlled query parameters, an attacker can append that path to requests aimed at other REST endpoints and cause a logged-in administrator's session to execute them with their existing privileges — producing, on a default installation, a new administrator account under the attacker's control. Patchstack notes the attack requires no JavaScript, no attacker-controlled webpage and no submitted form: a single link, delivered by email, chat message or a comment on the site, is sufficient, which is precisely the delivery profile that survives user-awareness training. Elementor shipped the fix in version 4.3.2 on 24 September, two days after the report. Releases before 4.3.0 do not contain the affected Editor Events proxy, but Patchstack notes older versions carry other flaws, some of which are already being actively exploited.

Attribute Detail
Sector Global (Macro)
Date 2026-09-28
Source BleepingComputer
Reliability Tier 2