Elementor CSRF Flaw Lets Attackers Take Over Sites
Headline by Prism · from 1 report
A high-severity CSRF vulnerability in the Elementor WordPress plugin allows attackers to create administrator accounts.
The Hacker NewsThe brief
Written by software from the 1 report below.
- A cross-site request forgery vulnerability exists in versions 4.3.0 and 4.3.1 of the Elementor Website Builder plugin.
- Attackers can gain administrative access by tricking a logged-in user into clicking a malicious link.
- The flaw allows unauthorized REST API actions, including the creation of rogue administrator accounts.
- Security researchers report that the vulnerability was addressed in version 4.3.2.
What to watch next
- Check for evidence of rogue administrator accounts on affected WordPress sites
- Ensure all Elementor plugin installations are updated to version 4.3.2 or later
The points restate the reports; where one says why it matters, that is Prism's reading, not a reported fact.
Who said what
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Patchstack
3 quotes · 1 outlet
“One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform”
In the article
…versions 4.3.0 and 4.3.1 of the plugin, which is active on over 10 million WordPress sites. Statistics from WordPress.org show that the two impacted versions alone have been installed on more than 2 million sites. " One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform ," Patchstack said. "On a stock installation, an administrator clicking the link creates a second administrator account for the attacker." The WordPress security company said the attack does not hinge on any…
“On a stock installation, an administrator clicking the link creates a second administrator account for the attacker.”
In the article
…versions alone have been installed on more than 2 million sites. "One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform," Patchstack said. " On a stock installation, an administrator clicking the link creates a second administrator account for the attacker. " The WordPress security company said the attack does not hinge on any prerequisite, such as JavaScript, a submitted form, or a web page under the threat actor's control. The link can even be a plain anchor tag embedded…
Coverage
1 outlet
All filed from India
NamedIndia · Elementor · Wordpress · Patchstack · Saggre
The 1 report is listed beside the record.
Corrections and versions
A correction says what was wrong and why. Every earlier headline and brief of this record is kept.
Something wrong?
Say what, and it arrives with this record's address filled in. A correction is welcome.
Ask this story
Answers cite the 1 report above, or say they can't.