Elementor WordPress 4.3.0–4.3.1 CSRF (Patchstack CVSS 8.8): one admin click → attacker admin via REST proxy — patch 4.3.2
Patchstack (Dave Jong, published 25 September 2026; reporter Saggre via Patchstack 22 Sep) details an unauthenticated cross-site request forgery in Elementor Website Builder 4.3.0 and 4.3.1 only. The Editor Events module checked the raw request URI for the elementor/v1/events/ path and skipped WordPress REST nonce validation when present, so attacker-controlled query parameters could append that path to other REST endpoints. A logged-in administrator opening a single link (email/chat/comment — no JavaScript or attacker page required) performs any REST action their role allows; on default installs that includes creating a new administrator. ~2 million sites on 4.3.0/4.3.1 per WordPress.org stats cited by BleepingComputer (25 Sep). Releases before 4.3.0 lack the Editor Events proxy (not this bug). Fixed in Elementor 4.3.2 (24 Sep) by validating the resolved REST route. No CVE ID assigned as of the Patchstack/BleepingComputer reports. Primary: Patchstack; wire: BleepingComputer.
- Product
- Elementor Website Builder (WordPress plugin)
- Versions
- Affected: 4.3.0 and 4.3.1 only. Fixed: 4.3.2 (24 September 2026). Pre-4.3.0 not affected by this Editor Events proxy bug.
- CVSS
- 8.8 (Patchstack; no CVE ID as of 25 Sep reports)
- Exploited in Australia?
- unknown
- Patch to
- Upgrade Elementor to 4.3.2 or later immediately; audit WordPress users for unexpected administrators created since 4.3.0/4.3.1 install; review access logs for REST calls carrying elementor/v1/events/ in the query string
Primary: Patchstack — CSRF in Elementor plugin affecting 2M+ sites (25 Sep 2026) · Vendor: WordPress.org — Elementor plugin (upgrade to 4.3.2+) · BleepingComputer — Elementor CSRF → admin accounts (25 Sep 2026)
