Critical Elementor CSRF Flaw Exposes Millions of WordPress Sites to Full Takeover

What Happened?
A critical Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Elementor Website Builder plugin for WordPress. The flaw affects versions 4.3.0 and 4.3.1, enabling an unauthenticated attacker to manipulate a logged-in administrator into executing unauthorized REST API commands.
Discovered by researcher 'Saggre' and reported by Patchstack, the vulnerability was promptly addressed by Elementor in version 4.3.2. With the plugin active on 10 million sites total, and the vulnerable versions deployed on roughly 2 million, the potential attack surface is massive.
Why It Matters
This incident underscores the fragility of complex plugin architectures that attempt to shortcut core security protocols. By bypassing WordPress REST nonce validation through improper URI parsing, the plugin inadvertently provided a pathway for privilege escalation. In a typical default installation, the successful exploitation of this flaw leads to the creation of a rogue administrator account, granting the attacker total control over the victim's website environment.
Key Details & Takeaways
- Up to 2 million WordPress sites were exposed across versions 4.3.0 and 4.3.1.
- The flaw originated from the Editor Events module, which incorrectly bypassed native REST nonce security checks.
- Users are urged to update to version 4.3.2 immediately to mitigate the risk of account takeover and site compromise.