Security researchers have disclosed a high-severity cross-site request forgery flaw in Elementor Website Builder versions 4.3.0 and 4.3.1. The weakness could allow a crafted link opened by a logged-in WordPress administrator to perform REST API actions with that administrator’s permissions, including creating another privileged account on a default installation.
The flaw extended beyond one Elementor route
Patchstack traced the issue to the Editor Events module, which exempted requests from WordPress nonce checks when a particular Elementor route string appeared anywhere in the request URI. Because an attacker could place that string in a query parameter, the exemption could affect other WordPress core or plugin REST routes. The attack did not require a malicious page or JavaScript; the trigger could be an ordinary link delivered through email, chat or a comment.
The affected module is present only in the two identified releases. Patchstack says the issue was addressed in Elementor 4.3.2 following responsible disclosure. Administrators should verify the installed version and update through their normal change-control process.
Session context remains a critical control
The attack depends on a privileged user being authenticated when the link is opened. Organizations can reduce exposure through rapid patching, limited administrator accounts, separate browsing practices and review of newly created users. Security teams should also inspect audit logs for unexpected REST activity. SectechMedia tracks related risks in its cyber-physical security coverage.

Leave a Reply