Elementor WordPress flaw lets attackers create admin accounts

Elementor WordPress flaw lets attackers create admin accounts
A CSRF vulnerability in the Elementor WordPress plugin can let an attacker trick a logged-in administrator into creating a new attacker-controlled admin account through a crafted link. The flaw affects Elementor versions 4.3.0 and 4.3.1, and users are urged to upgrade to 4.3.2 to block the REST API bypass. #Elementor #Patchstack #WordPress

Keypoints

  • The CSRF flaw affects Elementor versions 4.3.0 and 4.3.1.
  • A logged-in administrator can be tricked into triggering a REST API action.
  • The issue can allow creation of an attacker-controlled administrator account.
  • Patchstack reported the vulnerability after receiving it from bug hunter Saggre.
  • Elementor fixed the problem in version 4.3.2.

Read More: https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/