Critical CSRF Vulnerability in Elementor Plugin Poses Security Risk
A severe cross-site request forgery (CSRF) vulnerability has been identified within the Elementor plugin for WordPress, potentially enabling an unauthenticated assailant to establish administrator accounts.
Exploitation of this flaw ensues when a logged-in administrator is duped into clicking on a malicious link, which subsequently leverages the victim’s authenticated session to execute a REST API action permitted by their account’s privileges.
In standard installations, the consequence is the formation of an administrator account subject to the attacker’s control.
The Elementor Website Builder, a widely utilized WordPress plugin, supports around 10 million websites and facilitates users in crafting websites through an intuitive drag-and-drop interface.
The identified CSRF vulnerability, which remains without an assigned identifier, affects only versions 4.3.0 and 4.3.1. According to data from WordPress.org, these versions are operational on up to 2 million sites.
On September 22, security firm Patchstack alerted the Elementor team regarding this vulnerability, having received notice from bug bounty researcher “Saggre.” A remedial update, version 4.3.2, was issued by Elementor just two days later.
Patchstack’s investigation contends that this CSRF vulnerability is rooted in Elementor’s Editor Events module, which erroneously checks the raw request URI for the elementor/v1/events/ path, thereby circumventing WordPress’s REST nonce validation when that specific string is identified.
Given that the URI also encompasses attacker-controlled query parameters, malicious actors can append the vulnerable path to requests aimed at other REST endpoints, convincing logged-in users to execute them with their current permissions.
According to Patchstack, this vulnerability can be exploited in a one-click attack against a logged-in administrator, resulting in the creation of a new admin account manipulated by the attacker.
“One link, opened by a logged-in WordPress user, enables that user to perform any REST API action their account is authorized to execute,” Patchstack elaborates.

Significantly, the attack does not necessitate JavaScript, an adversary-controlled webpage, or form submissions; the malicious link may be disseminated via email, chat, or even comments on the site.
While versions of Elementor released prior to 4.3.0 do not contain the flawed Editor Events proxy, they are still susceptible to various vulnerabilities, some of which are known to be actively exploited.
Users of the Elementor plugin are strongly advised to upgrade to version 4.3.2 promptly, which thwarts attackers from activating the bypass through the query string.
Source link: Bleepingcomputer.com.



