Elementor WordPress flaw lets attackers create admin accounts

Executive Summary

A cross‑site request forgery (CSRF) flaw in the Elementor WordPress plugin allows unauthenticated attackers to create new administrator accounts, potentially giving them full site control. The vulnerability can be exploited without prior authentication and is not mitigated by default WordPress security settings.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-25T18:13:33+00:00 - Category: vulnerabilities

Original Description: A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]

"Simply put, you believer that things or people make you unhappy, but this is not accurate. You make yourself unhappy."

— Wayne Dyer
Source: Bleeping Computer