Find notable cyber news and cases, enriched with sources, timelines, and signals.

Elementor plugin WordPress CSRF admin account creation security flaw

Vulnerability
First reported
Last updated
Happening score
H score 1
1 unique sources, 1 articles

Summary

Hide ▲

A CSRF vulnerability in the Elementor plugin for WordPress lets an unauthenticated attacker force a logged-in administrator to perform REST API actions that can create attacker-controlled administrator accounts. The flaw affects versions 4.3.0 and 4.3.1, and Elementor has already shipped a fix in 4.3.2.

Related Happenings

Elementor CSRF bypass mitigation (4.3.2)

Advisory/Mitigation
H score37 First: 25.09.2026 21:13 Last: 25.09.2026 21:13 Sources 1

How related: Users of the plugin are recommended to upgrade to Elementor version 4.3.2 as soon as possible, which prevents attackers from triggering the bypass through the query string.

About this happening: Elementor users are being told to upgrade to version 4.3.2 immediately to block a CSRF bypass that can let a logged-in administrator perform attacker-triggered REST AP...

WP Toolkit cross-account database modification security flaw (CVE-2026-87900)

Vulnerability
H score1 First: 23.09.2026 15:16 Last: 23.09.2026 15:16 Sources 1

About this happening: The WP Toolkit flaw CVE-2026-87900 lets a logged-in cPanel user change databases in other accounts, creating cross-account data-integrity risk on shared hosting system...

WooCommerce Wholesale Lead Capture actively exploited arbitrary file-upload vulnerability (CVE-2026-27540)

Vulnerability
H score16 First: 15.09.2026 17:45 Last: 15.09.2026 17:45 Sources 1

About this happening: CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin is being actively exploited, putting version 2.0.3.1 and older at risk of PHP webshell...

Elementor Pro Forms File Upload unauthenticated upload RCE (CVE-2026-32475)

Vulnerability
H score24 First: 20.08.2026 09:04 Last: 20.08.2026 09:04 Sources 1

About this happening: CVE-2026-32475 is a critical Elementor Pro file-upload vulnerability that lets an unauthenticated attacker bypass checks in the Forms module's File Upload field, w...

Latest development: 03.09.2026 17:52

Wordfence says exploitation of CVE-2026-32475 in Elementor Pro started on August 19, the same day Elementor released 4.2.2, and its web application firewall later observed increased attack activity between August 19 and 23 while blocking almost 200,000 exploitation attempts targeting its clients. The attack path uses the Forms module's File Upload field to place a PHP payload under /wp-content/uploads/elementor/forms/ and execute arbitrary commands on affected WordPress servers.

WordPress login screen pre-auth reflected XSS (CVE-2026-64638)

Vulnerability
H score24 First: 07.08.2026 15:56 Last: 07.08.2026 15:56 Sources 1

About this happening: WordPress patched CVE-2026-64638, a pre-auth reflected XSS in the login screen that affects every version of the CMS. The flaw can be chained under additional...

Timeline

  1. 25.09.2026 21:13 2 articles · 2h ago

    Patchstack reports Elementor CSRF flaw to Elementor

    Initial Disclosure

    Patchstack reported a CSRF vulnerability in the Elementor WordPress plugin to the Elementor team after receiving it from bug hunter Saggre; the flaw affects versions 4.3.0 and 4.3.1 and can let an attacker force a logged-in administrator to create attacker-controlled administrator accounts through a malicious link.

    Show sources
  2. 25.09.2026 21:13 1 articles · 2h ago

    Elementor releases version 4.3.2 to block the CSRF bypass

    Mitigation Patch Update

    Elementor shipped version 4.3.2 to stop attackers from triggering the Editor Events request-URI bypass through the query string and close the WordPress REST nonce validation issue in the affected plugin.

    Show sources