Elementor plugin WordPress CSRF admin account creation security flaw
Vulnerability
Summary
Hide ▲
Show ▼
A CSRF vulnerability in the Elementor plugin for WordPress lets an unauthenticated attacker force a logged-in administrator to perform REST API actions that can create attacker-controlled administrator accounts. The flaw affects versions 4.3.0 and 4.3.1, and Elementor has already shipped a fix in 4.3.2.
Related Happenings
Elementor CSRF bypass mitigation (4.3.2)
Advisory/Mitigation
H score37
First: 25.09.2026 21:13
Last: 25.09.2026 21:13
Sources 1
How related:
Users of the plugin are recommended to upgrade to Elementor version 4.3.2 as soon as possible, which prevents attackers from triggering the bypass through the query string.
About this happening:
Elementor users are being told to upgrade to version 4.3.2 immediately to block a CSRF bypass that can let a logged-in administrator perform attacker-triggered REST AP...
Elementor CSRF bypass mitigation (4.3.2)
Advisory/MitigationHow related: Users of the plugin are recommended to upgrade to Elementor version 4.3.2 as soon as possible, which prevents attackers from triggering the bypass through the query string.
About this happening: Elementor users are being told to upgrade to version 4.3.2 immediately to block a CSRF bypass that can let a logged-in administrator perform attacker-triggered REST AP...
WP Toolkit cross-account database modification security flaw (CVE-2026-87900)
Vulnerability
H score1
First: 23.09.2026 15:16
Last: 23.09.2026 15:16
Sources 1
About this happening:
The WP Toolkit flaw CVE-2026-87900 lets a logged-in cPanel user change databases in other accounts, creating cross-account data-integrity risk on shared hosting system...
WP Toolkit cross-account database modification security flaw (CVE-2026-87900)
VulnerabilityAbout this happening: The WP Toolkit flaw CVE-2026-87900 lets a logged-in cPanel user change databases in other accounts, creating cross-account data-integrity risk on shared hosting system...
WooCommerce Wholesale Lead Capture actively exploited arbitrary file-upload vulnerability (CVE-2026-27540)
Vulnerability
H score16
First: 15.09.2026 17:45
Last: 15.09.2026 17:45
Sources 1
About this happening:
CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin is being actively exploited, putting version 2.0.3.1 and older at risk of PHP webshell...
WooCommerce Wholesale Lead Capture actively exploited arbitrary file-upload vulnerability (CVE-2026-27540)
VulnerabilityAbout this happening: CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin is being actively exploited, putting version 2.0.3.1 and older at risk of PHP webshell...
Elementor Pro Forms File Upload unauthenticated upload RCE (CVE-2026-32475)
Vulnerability
H score24
First: 20.08.2026 09:04
Last: 20.08.2026 09:04
Sources 1
About this happening:
CVE-2026-32475 is a critical Elementor Pro file-upload vulnerability that lets an unauthenticated attacker bypass checks in the Forms module's File Upload field, w...
Elementor Pro Forms File Upload unauthenticated upload RCE (CVE-2026-32475)
VulnerabilityAbout this happening: CVE-2026-32475 is a critical Elementor Pro file-upload vulnerability that lets an unauthenticated attacker bypass checks in the Forms module's File Upload field, w...
Latest development: 03.09.2026 17:52
Wordfence says exploitation of CVE-2026-32475 in Elementor Pro started on August 19, the same day Elementor released 4.2.2, and its web application firewall later observed increased attack activity between August 19 and 23 while blocking almost 200,000 exploitation attempts targeting its clients. The attack path uses the Forms module's File Upload field to place a PHP payload under /wp-content/uploads/elementor/forms/ and execute arbitrary commands on affected WordPress servers.
WordPress login screen pre-auth reflected XSS (CVE-2026-64638)
Vulnerability
H score24
First: 07.08.2026 15:56
Last: 07.08.2026 15:56
Sources 1
About this happening:
WordPress patched CVE-2026-64638, a pre-auth reflected XSS in the login screen that affects every version of the CMS. The flaw can be chained under additional...
WordPress login screen pre-auth reflected XSS (CVE-2026-64638)
VulnerabilityAbout this happening: WordPress patched CVE-2026-64638, a pre-auth reflected XSS in the login screen that affects every version of the CMS. The flaw can be chained under additional...
Timeline
-
25.09.2026 21:13 2 articles · 2h ago
Patchstack reports Elementor CSRF flaw to Elementor
Initial DisclosurePatchstack reported a CSRF vulnerability in the Elementor WordPress plugin to the Elementor team after receiving it from bug hunter Saggre; the flaw affects versions 4.3.0 and 4.3.1 and can let an attacker force a logged-in administrator to create attacker-controlled administrator accounts through a malicious link.
Show sources
- Elementor WordPress flaw lets attackers create admin accounts — www.bleepingcomputer.com — 25.09.2026 21:13
- Elementor WordPress flaw lets attackers create admin accounts — www.bleepingcomputer.com — 25.09.2026 21:13
-
25.09.2026 21:13 1 articles · 2h ago
Elementor releases version 4.3.2 to block the CSRF bypass
Mitigation Patch UpdateElementor shipped version 4.3.2 to stop attackers from triggering the Editor Events request-URI bypass through the query string and close the WordPress REST nonce validation issue in the affected plugin.
Show sources
- Elementor WordPress flaw lets attackers create admin accounts — www.bleepingcomputer.com — 25.09.2026 21:13