Elementor plugin for WordPress security fix in 4.3.2
Security Patch Release
Summary
Hide ▲
Show ▼
The Elementor team shipped version 4.3.2 of the Elementor plugin for WordPress to fix a CSRF flaw that could let attackers create administrator accounts on vulnerable sites. The release closes the bypass affecting versions 4.3.0 and 4.3.1, which were installed on as many as 2 million sites. Site operators should upgrade to 4.3.2 to block the REST API abuse path.
Related Happenings
Elementor CSRF bypass mitigation (4.3.2)
Advisory/Mitigation
H score37
First: 25.09.2026 21:13
Last: 25.09.2026 21:13
Sources 1
How related:
Users of the plugin are recommended to upgrade to Elementor version 4.3.2 as soon as possible, which prevents attackers from triggering the bypass through the query string.
About this happening:
Elementor users are being told to upgrade to version 4.3.2 immediately to block a CSRF bypass that can let a logged-in administrator perform attacker-triggered REST AP...
Elementor CSRF bypass mitigation (4.3.2)
Advisory/MitigationHow related: Users of the plugin are recommended to upgrade to Elementor version 4.3.2 as soon as possible, which prevents attackers from triggering the bypass through the query string.
About this happening: Elementor users are being told to upgrade to version 4.3.2 immediately to block a CSRF bypass that can let a logged-in administrator perform attacker-triggered REST AP...
WordPress core security release (7.1.1)
Security Patch Release
H score45
First: 18.09.2026 19:56
Last: 18.09.2026 19:56
Sources 1
About this happening:
WordPress 7.1.1 is a security release that fixed the Click2Shell WordPress Core flaw, a CSRF issue that could let a logged-in administrator open a crafted...
WordPress core security release (7.1.1)
Security Patch ReleaseAbout this happening: WordPress 7.1.1 is a security release that fixed the Click2Shell WordPress Core flaw, a CSRF issue that could let a logged-in administrator open a crafted...
WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)
Security Patch Release
H score9
First: 15.09.2026 17:45
Last: 15.09.2026 17:45
Sources 1
About this happening:
The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upl...
WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)
Security Patch ReleaseAbout this happening: The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upl...
Elementor Pro 4.2.2 security update for CVE-2026-32475
Security Patch Release
H score27
First: 20.08.2026 09:04
Last: 20.08.2026 09:04
Sources 1
About this happening:
Elementor Pro released version 4.2.2 on August 19, 2026 to fix CVE-2026-32475, a critical unauthenticated file-upload RCE in the plugin’s Forms module File U...
Elementor Pro 4.2.2 security update for CVE-2026-32475
Security Patch ReleaseAbout this happening: Elementor Pro released version 4.2.2 on August 19, 2026 to fix CVE-2026-32475, a critical unauthenticated file-upload RCE in the plugin’s Forms module File U...
Elementor Ally 4.1.0 security patch release (CVE-2026-2313)
Security Patch Release
H score59
First: 11.03.2026 21:38
Last: 11.03.2026 21:38
Sources 1
About this happening:
Elementor released Ally 4.1.0 to fix CVE-2026-2313, a SQL injection flaw in the WordPress accessibility plugin that could expose sensitive data. The update lan...
Elementor Ally 4.1.0 security patch release (CVE-2026-2313)
Security Patch ReleaseAbout this happening: Elementor released Ally 4.1.0 to fix CVE-2026-2313, a SQL injection flaw in the WordPress accessibility plugin that could expose sensitive data. The update lan...
Timeline
-
25.09.2026 21:13 1 articles · 2h ago
Patchstack reports Elementor CSRF flaw to Elementor team
Initial DisclosurePatchstack reported a cross-site request forgery vulnerability in the Elementor WordPress plugin to the Elementor team after receiving it from bug hunter “Saggre.” The flaw affected versions 4.3.0 and 4.3.1 and could let an unauthenticated attacker create attacker-controlled administrator accounts by tricking a logged-in administrator into opening a malicious link that caused the victim's authenticated session to perform a REST API action.
Show sources
- Elementor WordPress flaw lets attackers create admin accounts — www.bleepingcomputer.com — 25.09.2026 21:13
-
25.09.2026 21:13 2 articles · 2h ago
Elementor releases version 4.3.2 to close the CSRF bypass
Mitigation Patch UpdateElementor released version 4.3.2 of the Elementor plugin for WordPress, addressing the CSRF flaw that let attackers create administrator accounts through a logged-in user's authenticated session. The fix blocks the REST nonce bypass tied to the elementor/v1/events/ path and the query-string behavior described by Patchstack, and users are advised to upgrade to 4.3.2 as soon as possible.
Show sources
- Elementor WordPress flaw lets attackers create admin accounts — www.bleepingcomputer.com — 25.09.2026 21:13
- Elementor WordPress flaw lets attackers create admin accounts — www.bleepingcomputer.com — 25.09.2026 21:13