Critical Elementor CSRF Bug Enables Site Takeover via Crafted Link

A serious security issue has been uncovered in the Elementor Website Builder plugin for WordPress — versions 4.3.0 and 4.3.1 are vulnerable to a cross-site request forgery (CSRF) flaw that allows attackers to gain full control of compromised sites.

What’s at Risk?

The flaw enables unauthenticated attackers to craft a link which, when clicked by a logged-in WordPress administrator, triggers REST API actions the admin is permitted to execute — including creating a new administrator account. This can happen without any form submissions, scripts, or interaction with pages under the attacker’s control; even a simple link shared via email or chat can cause damage. On a default setup, an attacker’s link makes the administrator unknowingly grant them full site access. The vulnerability has been assigned a CVSS severity score of 8.8 out of 10.

Where it’s Found & How it Works

Only Elementor versions 4.3.0 and 4.3.1 carry this issue. The Editor Events module in those releases skips CSRF protection for any cookie-authenticated REST API request where the request URI contains the string “elementor/v1/events/” anywhere in it. Because the URI check includes query parameters, an attacker can insert a seemingly innocuous parameter so that the request bypasses CSRF defenses entirely.

This loophole opens up the REST API surface of the WordPress site — affecting routes in the core system and any other installed plugin. As an example, sending a POST request to “/wp/v2/users” with parameters including roles[]=administrator will successfully add an administrator account — simply by embedding “elementor/v1/events/” into the URI’s query part.

Impact & Patch

Elementor is massively popular — with over 10 million installations. Of those, more than 2 million sites are running the risky versions identified. Because earlier versions lack the Editor Events proxy, those prior versions are unaffected.

The risk is already addressed: version 4.3.2 of the plugin is out with a fix. It’s strongly recommended that all site administrators update without delay. The vulnerability was discovered and reported by a researcher known as “Saggre.”

For clarity: the fix restores CSRF protections on affected REST API endpoints and ensures the Editor Events module no longer skips checks based on request URIs.

Why this matters: This bug illustrates how bypassing CSRF protections — even with a single string in a request — can completely undermine site security. It’s a reminder that every part of the API needs robust defenses. If you use Elementor 4.3.0 or 4.3.1, update immediately and verify whether any unauthorized administrator accounts have been added. Monitoring REST API logs and limiting admin clicks on untrusted content can reduce risk until you’re patched.