One link in Elementor 4.3 can make an admin create another admin

By George Bailey   Published: 09/30/26   4 min read

Patchstack’s research team showed that Elementor Website Builder 4.3.0 and 4.3.1 will skip WordPress’s REST CSRF check if the string elementor/v1/events/ appears anywhere in the request URI, including the query string. A logged-in administrator who clicks a single crafted link can create a second administrator account for the attacker. No JavaScript and no attacker-controlled page are required.

Elementor is active on more than ten million sites. The bad window is short (two releases), but it is wide. Confirm you are on 4.3.2 or newer before the next inbox scroll.

If your page builder can turn a GET into a new admin, treat the plugin update like a password reset.

What happened

Researcher Saggre reported the bug to Patchstack on Sep 22, 2026. Elementor shipped 4.3.2 on Sep 24. Patchstack published the advisory on Sep 25.

The vulnerable Editor Events module registers a rest_authentication_errors filter at priority 0. It decides “this is my route” with an unanchored strpos() over the raw REQUEST_URI. Because that string includes the query string, any REST request can opt out of cookie nonce checks by appending a harmless-looking parameter. Returning true tells every later handler, including WordPress core’s CSRF check, that authentication already succeeded.

WordPress also accepts _method=POST on a GET, so the entire attack fits in one URL mailed or messaged to an admin. Patchstack confirmed /wp/v2/users returns HTTP 201 with an administrator role when the bypass string is present, and that reading /wp/v2/settings flips from 401 to 200. The bypass applies to the whole REST surface, not only Elementor’s own endpoints. Sites whose first Elementor install was 3.32.0 or later had the hidden experiment on by default.

Why it matters

This is social engineering with a one-click finish line. Help desks, freelancers, and marketing admins click links all day. A plugin that turns those clicks into REST writes is an account-takeover factory sitting next to your content workflow.

The blast radius is every REST route the victim can reach, including routes from other plugins. Updating Elementor closes the door; it does not remove an admin account someone already created.

What to do first

Forward this

If anyone on your team manages WordPress sites that run Elementor: please confirm they are on version 4.3.2 or newer. Versions 4.3.0 and 4.3.1 let a single crafted link create a new administrator when a logged-in admin clicks it. Ask for a version screenshot and a quick check that no mystery admin accounts appeared this week.

Details

Hunt / verify

Slack paste: WordPress/Elementor: confirm Elementor >= 4.3.2 (not 4.3.0/4.3.1), audit admin users created since Sep 22, hunt /wp-json/* requests whose query string contains elementor/v1/events/.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.