Patchstack’s research team showed that Elementor Website Builder 4.3.0 and 4.3.1 will skip WordPress’s REST CSRF check if the string elementor/v1/events/ appears anywhere in the request URI, including the query string. A logged-in administrator who clicks a single crafted link can create a second administrator account for the attacker. No JavaScript and no attacker-controlled page are required.
Elementor is active on more than ten million sites. The bad window is short (two releases), but it is wide. Confirm you are on 4.3.2 or newer before the next inbox scroll.
If your page builder can turn a GET into a new admin, treat the plugin update like a password reset.
The 5-Minute Cyber BriefDon’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What happened
Researcher Saggre reported the bug to Patchstack on Sep 22, 2026. Elementor shipped 4.3.2 on Sep 24. Patchstack published the advisory on Sep 25.
The vulnerable Editor Events module registers a rest_authentication_errors filter at priority 0. It decides “this is my route” with an unanchored strpos() over the raw REQUEST_URI. Because that string includes the query string, any REST request can opt out of cookie nonce checks by appending a harmless-looking parameter. Returning true tells every later handler, including WordPress core’s CSRF check, that authentication already succeeded.
WordPress also accepts _method=POST on a GET, so the entire attack fits in one URL mailed or messaged to an admin. Patchstack confirmed /wp/v2/users returns HTTP 201 with an administrator role when the bypass string is present, and that reading /wp/v2/settings flips from 401 to 200. The bypass applies to the whole REST surface, not only Elementor’s own endpoints. Sites whose first Elementor install was 3.32.0 or later had the hidden experiment on by default.
Why it matters
This is social engineering with a one-click finish line. Help desks, freelancers, and marketing admins click links all day. A plugin that turns those clicks into REST writes is an account-takeover factory sitting next to your content workflow.
The blast radius is every REST route the victim can reach, including routes from other plugins. Updating Elementor closes the door; it does not remove an admin account someone already created.
What to do first
- Update Elementor to 4.3.2 or later on every site, including staging copies editors still use.
- List administrators. Compare
wp_users/ Users screen against your known admin set. Remove anything created since Sep 22 that you cannot explain. - Review application passwords and JWT plugins that might have been created through REST during the same window.
- Tighten who is an Administrator. Editor and Shop Manager roles do not need to create users.
- Keep Patchstack / Wordfence style virtual patches in place until the fleet is verified.
Forward this
If anyone on your team manages WordPress sites that run Elementor: please confirm they are on version 4.3.2 or newer. Versions 4.3.0 and 4.3.1 let a single crafted link create a new administrator when a logged-in admin clicks it. Ask for a version screenshot and a quick check that no mystery admin accounts appeared this week.
Details
- Affected: Elementor Website Builder 4.3.0 and 4.3.1 only
- Fixed: 4.3.2 (Sep 24, 2026)
- Issue: Unauthenticated CSRF to privilege escalation via REST nonce bypass (CVSS 8.8 per Patchstack)
- Trigger: substring
elementor/v1/events/in the request URI, including query string - Impact: any REST action the victim’s role allows, including creating an administrator via
/wp/v2/users - Reporter: Saggre via Patchstack; public advisory Sep 25, 2026
Hunt / verify
- Inventory Elementor versions across the fleet; flag anything still on 4.3.0 or 4.3.1.
- Search web server and WAF logs for
elementor/v1/events/inside query strings on/wp-json/paths, especially with_method=POSTand/wp/v2/users. - Diff the Users list against a known-good export from before Sep 22.
- Check for unexpected application passwords, new OAuth apps, and plugin installs after Sep 22.
Slack paste: WordPress/Elementor: confirm Elementor >= 4.3.2 (not 4.3.0/4.3.1), audit admin users created since Sep 22, hunt /wp-json/* requests whose query string contains elementor/v1/events/.
Sources
- Patchstack: Cross-Site Request Forgery in Elementor Plugin Affecting 2 Million+ Sites (Sep 25, 2026)
- Elementor plugin changelog (4.3.2)
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.