<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/elementor-wordpress-flaw-lets-attackers-create-admin-accounts-milveh7ja" -->

---
title: Elementor WordPress flaw lets attackers create admin...
description: A cross-site request forgery vulnerability in the Elementor WordPress plugin, affecting versions 4.3.0 and 4.3.1, lets an unauthenticated attacker trick a...
canonical: https://daily.dev/posts/elementor-wordpress-flaw-lets-attackers-create-admin-accounts-milveh7ja
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Elementor WordPress flaw lets attackers create admin accounts | daily.dev
og:description: A cross-site request forgery vulnerability in the Elementor WordPress plugin, affecting versions 4.3.0 and 4.3.1, lets an unauthenticated attacker trick a...
og:url: https://daily.dev/posts/elementor-wordpress-flaw-lets-attackers-create-admin-accounts-milveh7ja
og:image: https://api.daily.dev/og/posts/MilveH7ja.png
og:image:alt: Elementor WordPress flaw lets attackers create admin accounts
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Elementor WordPress flaw lets attackers create admin accounts

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

A cross-site request forgery vulnerability in the Elementor WordPress plugin, affecting versions 4.3.0 and 4.3.1, lets an unauthenticated attacker trick a logged-in administrator into clicking a malicious link that creates a new attacker-controlled admin account. The bug stems from Elementor's Editor Events module bypassing WordPress's REST nonce validation when it detects the elementor/v1/events/ path in the raw request URI, allowing attackers to append that string to other REST endpoint requests. Patchstack reported the issue on September 22, and Elementor shipped a fix in version 4.3.2 two days later. Up to 2 million sites run the affected versions out of Elementor's 10 million total installs.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts>

## Questions this post answers

### Is Elementor version 4.3.1 vulnerable to a CSRF attack that creates admin accounts?

Yes, Elementor versions 4.3.0 and 4.3.1 contain a CSRF flaw in the Editor Events module that bypasses WordPress's REST nonce validation, letting attackers trick a logged-in administrator into a one-click attack that creates a new attacker-controlled admin account. Elementor fixed the issue in version 4.3.2, released on September 24.

_Teams running Elementor should track plugin security advisories like this on daily.dev before patching decisions slip._

### How does the Elementor Editor Events CSRF bypass actually work?

The flaw occurs because Elementor's Editor Events module checks the raw request URI for the string elementor/v1/events/ and skips WordPress's REST nonce validation whenever that string appears. Since the URI also carries attacker-controlled query parameters, attackers append that path to requests targeting other REST endpoints, letting a victim's authenticated session execute unintended admin actions with no JavaScript, form, or malicious page required.

_Developers auditing WordPress plugin security follow writeups like this on daily.dev to spot similar nonce-bypass patterns._

### How many WordPress sites are affected by the Elementor CSRF vulnerability in versions 4.3.0 and 4.3.1?

Up to 2 million WordPress sites run the vulnerable Elementor versions 4.3.0 and 4.3.1, out of roughly 10 million total sites using the Elementor Website Builder plugin. Patchstack reported the flaw to Elementor on September 22, and a fix shipped two days later in version 4.3.2.

_Site owners assessing plugin risk exposure can keep tabs on disclosures like this via daily.dev._

## Similar posts on daily.dev

- [WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts](https://daily.dev/posts/wordpress-king-addons-flaw-under-active-attack-lets-hackers-make-admin-accounts-90n2qv4qa) · The Hacker News · 3 upvotes · 0 comments
- [Critical WordPress Plugin Vulnerability Allows Unauthenticated Admin Takeover on 150K Sites](https://daily.dev/posts/critical-wordpress-plugin-vulnerability-allows-unauthenticated-admin-takeover-on-150k-sites-2ap9ez0hm) · Orca Security Blog · 2 upvotes · 2 comments

---

Tags: [#security](https://daily.dev/tags/security), [#php](https://daily.dev/tags/php), [#wordpress](https://daily.dev/tags/wordpress)

[View this post on daily.dev](https://daily.dev/posts/elementor-wordpress-flaw-lets-attackers-create-admin-accounts-milveh7ja)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Elementor WordPress flaw lets attackers create admin accounts","url":"https://daily.dev/posts/elementor-wordpress-flaw-lets-attackers-create-admin-accounts-milveh7ja","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/elementor-wordpress-flaw-lets-attackers-create-admin-accounts-milveh7ja"},"datePublished":"2026-09-25T18:15:23.501Z","dateModified":"2026-09-25T18:15:46.454Z","description":"A cross-site request forgery vulnerability in the Elementor WordPress plugin, affecting versions 4.3.0 and 4.3.1, lets an unauthenticated attacker trick a...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/201984acbbf5af8db3a460d7f8b2ed71?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/201984acbbf5af8db3a460d7f8b2ed71?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/elementor-wordpress-flaw-lets-attackers-create-admin-accounts-milveh7ja","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,php,wordpress","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Elementor WordPress flaw lets attackers create admin accounts"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/elementor-wordpress-flaw-lets-attackers-create-admin-accounts-milveh7ja#faq","mainEntity":[{"@type":"Question","name":"Is Elementor version 4.3.1 vulnerable to a CSRF attack that creates admin accounts?","acceptedAnswer":{"@type":"Answer","text":"Yes, Elementor versions 4.3.0 and 4.3.1 contain a CSRF flaw in the Editor Events module that bypasses WordPress's REST nonce validation, letting attackers trick a logged-in administrator into a one-click attack that creates a new attacker-controlled admin account. Elementor fixed the issue in version 4.3.2, released on September 24. Teams running Elementor should track plugin security advisories like this on daily.dev before patching decisions slip."}},{"@type":"Question","name":"How does the Elementor Editor Events CSRF bypass actually work?","acceptedAnswer":{"@type":"Answer","text":"The flaw occurs because Elementor's Editor Events module checks the raw request URI for the string elementor/v1/events/ and skips WordPress's REST nonce validation whenever that string appears. Since the URI also carries attacker-controlled query parameters, attackers append that path to requests targeting other REST endpoints, letting a victim's authenticated session execute unintended admin actions with no JavaScript, form, or malicious page required. Developers auditing WordPress plugin security follow writeups like this on daily.dev to spot similar nonce-bypass patterns."}},{"@type":"Question","name":"How many WordPress sites are affected by the Elementor CSRF vulnerability in versions 4.3.0 and 4.3.1?","acceptedAnswer":{"@type":"Answer","text":"Up to 2 million WordPress sites run the vulnerable Elementor versions 4.3.0 and 4.3.1, out of roughly 10 million total sites using the Elementor Website Builder plugin. Patchstack reported the flaw to Elementor on September 22, and a fix shipped two days later in version 4.3.2. Site owners assessing plugin risk exposure can keep tabs on disclosures like this via daily.dev."}}]}
```

