# Security Brief: Elementor CSRF Flaw Can Create Rogue WordPress Administrator Accounts

Canonical: https://vulnify.app/blog/security-brief-elementor-csrf-rogue-wordpress-admin-accounts

Elementor 4.3.0 and 4.3.1 contain a high-severity CSRF flaw that can let a crafted link trigger privileged WordPress REST actions when opened by a logged-in administrator. Version 4.3.2 fixes the issue.

What happened A high-severity cross-site request forgery flaw has been disclosed in Elementor Website Builder versions 4.3.0 and 4.3.1. Patchstack says the issue can let an unauthenticated attacker make a logged-in WordPress user perform REST API actions that the victim account is already permitted to perform. On a standard installation, an administrator who opens a crafted link can be induced to create a second administrator account controlled by the attacker. The weakness is in Elementor's Editor Events module. A request-URI check can disable WordPress REST nonce protection when the string elementor/v1/events/ appears anywhere in the URI, including attacker-controlled query-string data. Elementor fixed the issue in version 4.3.2. Why it matters for website owners This is more serious than a CSRF issue limited to one Elementor action. The bypass occurs before REST routing, so the victim's existing permissions can apply across WordPress core routes and routes exposed by other installed plugins. The attack also does not require JavaScript or a malicious form. A normal-looking link in email, chat, or a comment can be enough if a privileged user opens it while authenticated. What to check on your site Check whether Elementor 4.3.0 or 4.3.1 is installed and update to 4.3.2 or later. Review WordPress administrator accounts for unexpected additions, privilege changes, or unfamiliar email addresses. Review REST and web access logs for unusual requests around /wp-json/ , especially activity involving user creation or settings changes. Use the WordPress Stack Checker for an external WordPress profile. Public scanning can support inventory and follow-up, but it cannot confirm whether this CSRF path was exploited. Related reading The Admin Panel Security Checklist covers administrator accounts, sessions, MFA, and privilege review. After updating Elementor, the Post-Deployment Website Security Checklist provides a practical validation sequence for the live site. Sources The Hacker News Patchstack
