Find notable cyber news and cases, enriched with sources, timelines, and signals.

Elementor plugin for WordPress security fix in 4.3.2

Security Patch Release
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

The Elementor team shipped version 4.3.2 of the Elementor plugin for WordPress to fix a CSRF flaw that could let attackers create administrator accounts on vulnerable sites. The release closes the bypass affecting versions 4.3.0 and 4.3.1, which were installed on as many as 2 million sites. Site operators should upgrade to 4.3.2 to block the REST API abuse path.

Related Happenings

Elementor CSRF bypass mitigation (4.3.2)

Advisory/Mitigation
H score37 First: 25.09.2026 21:13 Last: 25.09.2026 21:13 Sources 1

How related: Users of the plugin are recommended to upgrade to Elementor version 4.3.2 as soon as possible, which prevents attackers from triggering the bypass through the query string.

About this happening: Elementor users are being told to upgrade to version 4.3.2 immediately to block a CSRF bypass that can let a logged-in administrator perform attacker-triggered REST AP...

WordPress core security release (7.1.1)

Security Patch Release
H score45 First: 18.09.2026 19:56 Last: 18.09.2026 19:56 Sources 1

About this happening: WordPress 7.1.1 is a security release that fixed the Click2Shell WordPress Core flaw, a CSRF issue that could let a logged-in administrator open a crafted...

WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)

Security Patch Release
H score9 First: 15.09.2026 17:45 Last: 15.09.2026 17:45 Sources 1

About this happening: The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upl...

Elementor Pro 4.2.2 security update for CVE-2026-32475

Security Patch Release
H score27 First: 20.08.2026 09:04 Last: 20.08.2026 09:04 Sources 1

About this happening: Elementor Pro released version 4.2.2 on August 19, 2026 to fix CVE-2026-32475, a critical unauthenticated file-upload RCE in the plugin’s Forms module File U...

Elementor Ally 4.1.0 security patch release (CVE-2026-2313)

Security Patch Release
H score59 First: 11.03.2026 21:38 Last: 11.03.2026 21:38 Sources 1

About this happening: Elementor released Ally 4.1.0 to fix CVE-2026-2313, a SQL injection flaw in the WordPress accessibility plugin that could expose sensitive data. The update lan...

Timeline

  1. 25.09.2026 21:13 1 articles · 2h ago

    Patchstack reports Elementor CSRF flaw to Elementor team

    Initial Disclosure

    Patchstack reported a cross-site request forgery vulnerability in the Elementor WordPress plugin to the Elementor team after receiving it from bug hunter “Saggre.” The flaw affected versions 4.3.0 and 4.3.1 and could let an unauthenticated attacker create attacker-controlled administrator accounts by tricking a logged-in administrator into opening a malicious link that caused the victim's authenticated session to perform a REST API action.

    Show sources
  2. 25.09.2026 21:13 2 articles · 2h ago

    Elementor releases version 4.3.2 to close the CSRF bypass

    Mitigation Patch Update

    Elementor released version 4.3.2 of the Elementor plugin for WordPress, addressing the CSRF flaw that let attackers create administrator accounts through a logged-in user's authenticated session. The fix blocks the REST nonce bypass tied to the elementor/v1/events/ path and the query-string behavior described by Patchstack, and users are advised to upgrade to 4.3.2 as soon as possible.

    Show sources