// AI threat desk · 3 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesCriticalCSRFCVSS 8.8 out of 10.0

Elementor flaw could let logged-in users perform permitted REST actions

Patchstack reported the CSRF vulnerability on Sep 25, 2026, and Elementor fixed it in version 4.3.2. The Hacker News reported it on Sep 26, 2026, citing a CVSS score of 8.8 and no CVE identifier.

stock image, not from the event
File photo: stock image, not from the event. Photo: rawpixel (CC0)
Key takeaways
  • A link opened by a logged-in WordPress user could make that user perform any REST API action their account was permitted to perform.
  • The bypass applied across WordPress core routes and routes belonging to every other installed plugin.
  • On a stock installation, an administrator clicking one link could create a second administrator account for the attacker.
On this page

A request bypassed CSRF protection

Patchstack said Elementor disables WordPress core’s only CSRF protection for cookie-authenticated REST API requests when the literal string elementor/v1/events/ appears anywhere in the request URI.

The attack needed no JavaScript, form or attacker-controlled page. It could use a plain anchor in an email, chat message or comment.

Only two releases were affected

The vulnerability affected only Elementor versions 4.3.0 and 4.3.1, according to Patchstack. The Hacker News said those two versions had been installed on more than 2 million sites.

Elementor released a fix

Elementor fixed the vulnerability in version 4.3.2. Patchstack said Saggre discovered and reported the issue to it.

Patchstack also issued mitigation rules to protect against exploitation of the vulnerability.

How we checked this story
ClaimSourceStatus
Patchstack reported a CSRF vulnerability in the Elementor Website Builder plugin.PatchstackConfirmed
The vulnerability lets a logged-in WordPress user perform any REST API action their account is permitted to perform.PatchstackConfirmed
The Hacker News said the vulnerability has a CVSS score of 8.8 out of 10.0.The Hacker NewsAttributed
The vulnerability affects only Elementor versions 4.3.0 and 4.3.1.PatchstackConfirmed
Elementor is active on over ten million sites.PatchstackConfirmed
The Hacker News said the two affected versions have been installed on more than 2 million sites.The Hacker NewsAttributed
An administrator clicking one link on a stock installation can create a second administrator account for the attacker.PatchstackConfirmed
The attack needs no JavaScript, form, or attacker-controlled page.PatchstackConfirmed
The attack can use a plain anchor in an email, chat message, or comment.PatchstackConfirmed
Elementor disables CSRF protection when the literal string elementor/v1/events/ appears anywhere in the request URI.PatchstackConfirmed
The bypass applies to WordPress core routes and routes of every other installed plugin.PatchstackConfirmed
Elementor fixed the vulnerability in version 4.3.2.PatchstackConfirmed
Saggre discovered and reported the vulnerability to Patchstack.PatchstackConfirmed
The vulnerability had not been assigned a CVE identifier when The Hacker News reported it.The Hacker NewsAttributed
Patchstack issued mitigation rules to protect against exploitation of the vulnerability.PatchstackConfirmed
The Hacker News published its story on Sep 26, 2026.The Hacker NewsConfirmed
patchstack.com published its report on Sep 25, 2026.patchstack.comConfirmed

Could not verify

  • Whether the vulnerability has been exploited in the wild is not established.
  • Whether a CVE identifier was assigned after the reported disclosure is not established.
  • How many sites were actually vulnerable or compromised is not established.
  • Whether the vulnerability affected versions released before 4.3.0 is not established beyond the reported absence of the Editor Events proxy.

What to do now

  1. Update Elementor to version 4.3.2 or above.

FAQ

Was a CVE identifier assigned?

The Hacker News said the vulnerability had yet to be assigned a CVE identifier when it reported the issue.

Which versions should users check?

Patchstack said only Elementor versions 4.3.0 and 4.3.1 were affected, and it recommended version 4.3.2 or above.

Who reported the vulnerability to Patchstack?

Patchstack said Saggre discovered and reported the vulnerability to it.

Sources

  1. Cross-Site Request Forgery in Elementor Plugin Affecting 2 Million+ Sites - Patchstack, PatchstackPrimary
  2. Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link, The Hacker News
Explore with AI