A CSRF vulnerability in the Elementor WordPress plugin can let an attacker trick a logged-in administrator into creating a new attacker-controlled admin account through a crafted link. The flaw affects Elementor versions 4.3.0 and 4.3.1, and users are urged to upgrade to 4.3.2 to block the REST API bypass. #Elementor #Patchstack #WordPress
Keypoints
- The CSRF flaw affects Elementor versions 4.3.0 and 4.3.1.
- A logged-in administrator can be tricked into triggering a REST API action.
- The issue can allow creation of an attacker-controlled administrator account.
- Patchstack reported the vulnerability after receiving it from bug hunter Saggre.
- Elementor fixed the problem in version 4.3.2.