- A link opened by a logged-in WordPress user could make that user perform any REST API action their account was permitted to perform.
- The bypass applied across WordPress core routes and routes belonging to every other installed plugin.
- On a stock installation, an administrator clicking one link could create a second administrator account for the attacker.
On this page
A request bypassed CSRF protection
Patchstack said Elementor disables WordPress core’s only CSRF protection for cookie-authenticated REST API requests when the literal string elementor/v1/events/ appears anywhere in the request URI.
The attack needed no JavaScript, form or attacker-controlled page. It could use a plain anchor in an email, chat message or comment.
Only two releases were affected
The vulnerability affected only Elementor versions 4.3.0 and 4.3.1, according to Patchstack. The Hacker News said those two versions had been installed on more than 2 million sites.
Elementor released a fix
Elementor fixed the vulnerability in version 4.3.2. Patchstack said Saggre discovered and reported the issue to it.
Patchstack also issued mitigation rules to protect against exploitation of the vulnerability.
How we checked this story
| Claim | Source | Status |
|---|---|---|
| Patchstack reported a CSRF vulnerability in the Elementor Website Builder plugin. | Patchstack | Confirmed |
| The vulnerability lets a logged-in WordPress user perform any REST API action their account is permitted to perform. | Patchstack | Confirmed |
| The Hacker News said the vulnerability has a CVSS score of 8.8 out of 10.0. | The Hacker News | Attributed |
| The vulnerability affects only Elementor versions 4.3.0 and 4.3.1. | Patchstack | Confirmed |
| Elementor is active on over ten million sites. | Patchstack | Confirmed |
| The Hacker News said the two affected versions have been installed on more than 2 million sites. | The Hacker News | Attributed |
| An administrator clicking one link on a stock installation can create a second administrator account for the attacker. | Patchstack | Confirmed |
| The attack needs no JavaScript, form, or attacker-controlled page. | Patchstack | Confirmed |
| The attack can use a plain anchor in an email, chat message, or comment. | Patchstack | Confirmed |
| Elementor disables CSRF protection when the literal string elementor/v1/events/ appears anywhere in the request URI. | Patchstack | Confirmed |
| The bypass applies to WordPress core routes and routes of every other installed plugin. | Patchstack | Confirmed |
| Elementor fixed the vulnerability in version 4.3.2. | Patchstack | Confirmed |
| Saggre discovered and reported the vulnerability to Patchstack. | Patchstack | Confirmed |
| The vulnerability had not been assigned a CVE identifier when The Hacker News reported it. | The Hacker News | Attributed |
| Patchstack issued mitigation rules to protect against exploitation of the vulnerability. | Patchstack | Confirmed |
| The Hacker News published its story on Sep 26, 2026. | The Hacker News | Confirmed |
| patchstack.com published its report on Sep 25, 2026. | patchstack.com | Confirmed |
Could not verify
- Whether the vulnerability has been exploited in the wild is not established.
- Whether a CVE identifier was assigned after the reported disclosure is not established.
- How many sites were actually vulnerable or compromised is not established.
- Whether the vulnerability affected versions released before 4.3.0 is not established beyond the reported absence of the Editor Events proxy.
What to do now
- Update Elementor to version 4.3.2 or above.
FAQ
Was a CVE identifier assigned?
The Hacker News said the vulnerability had yet to be assigned a CVE identifier when it reported the issue.
Which versions should users check?
Patchstack said only Elementor versions 4.3.0 and 4.3.1 were affected, and it recommended version 4.3.2 or above.
Who reported the vulnerability to Patchstack?
Patchstack said Saggre discovered and reported the vulnerability to it.



