Elementor Vulnerability in WordPress Allows Attackers to Generate Admin Accounts

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Critical CSRF Vulnerability in Elementor Plugin Poses Security Risk

A severe cross-site request forgery (CSRF) vulnerability has been identified within the Elementor plugin for WordPress, potentially enabling an unauthenticated assailant to establish administrator accounts.

Exploitation of this flaw ensues when a logged-in administrator is duped into clicking on a malicious link, which subsequently leverages the victim’s authenticated session to execute a REST API action permitted by their account’s privileges.

In standard installations, the consequence is the formation of an administrator account subject to the attacker’s control.

The Elementor Website Builder, a widely utilized WordPress plugin, supports around 10 million websites and facilitates users in crafting websites through an intuitive drag-and-drop interface.

The identified CSRF vulnerability, which remains without an assigned identifier, affects only versions 4.3.0 and 4.3.1. According to data from WordPress.org, these versions are operational on up to 2 million sites.

On September 22, security firm Patchstack alerted the Elementor team regarding this vulnerability, having received notice from bug bounty researcher “Saggre.” A remedial update, version 4.3.2, was issued by Elementor just two days later.

Patchstack’s investigation contends that this CSRF vulnerability is rooted in Elementor’s Editor Events module, which erroneously checks the raw request URI for the elementor/v1/events/ path, thereby circumventing WordPress’s REST nonce validation when that specific string is identified.

Given that the URI also encompasses attacker-controlled query parameters, malicious actors can append the vulnerable path to requests aimed at other REST endpoints, convincing logged-in users to execute them with their current permissions.

According to Patchstack, this vulnerability can be exploited in a one-click attack against a logged-in administrator, resulting in the creation of a new admin account manipulated by the attacker.

“One link, opened by a logged-in WordPress user, enables that user to perform any REST API action their account is authorized to execute,” Patchstack elaborates.

Person wearing a WordPress t-shirt types on a keyboard at a desk with a computer monitor and a mug labeled WordPress OKULLU.

Significantly, the attack does not necessitate JavaScript, an adversary-controlled webpage, or form submissions; the malicious link may be disseminated via email, chat, or even comments on the site.

While versions of Elementor released prior to 4.3.0 do not contain the flawed Editor Events proxy, they are still susceptible to various vulnerabilities, some of which are known to be actively exploited.

Users of the Elementor plugin are strongly advised to upgrade to version 4.3.2 promptly, which thwarts attackers from activating the bypass through the query string.

Source link: Bleepingcomputer.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading