#9
The Hacker News
general
September 26, 2026 at 09:55 UTC
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
By [email protected] (The Hacker News)
AI Summary
A high-severity CSRF vulnerability (CVSS 8.8) in the Elementor Website Builder WordPress plugin — which has tens of millions of installs — allows unauthenticated attackers to create rogue administrator accounts if an existing admin clicks a crafted link. No CVE has been assigned yet, and admins should verify plugin versions and apply available patches immediately.
Relevance score: 76.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →