Elementor 4.3.2 fixes a one-click flaw that lets attackers create WordPress administrators
EditorialBy TrustList Editorial
A cross-site request forgery flaw in Elementor 4.3.0 and 4.3.1 lets a crafted link, opened by a logged-in administrator, create a new admin account. Version 4.3.2, released 24 September, fixes it. Earlier versions are not affected.
About Elementor 4.3.2 fixes a one-click flaw that lets attackers create WordPress administrators
Elementor 4.3.2 fixes a one-click flaw that lets attackers create WordPress administrators
24 September 2026 — Elementor, the page-builder plugin for WordPress, released version 4.3.2 on 24 September 2026, fixing a cross-site request forgery flaw that lets an attacker create an administrator account on a site. The attacker only needs a logged-in administrator to open a crafted link. The flaw exists only in versions 4.3.0 and 4.3.1, released on 22 and 23 September, so sites that have not updated in the past week are not affected, but sites that update automatically to every release may have run a vulnerable version.
What the flaw does
According to the security firm Patchstack, whose analysis both BleepingComputer and The Hacker News report, the plugin's new Editor Events module checks the raw request address for the text elementor/v1/events/ and, when it finds it, skips WordPress's normal check that a request really came from the site. By adding that text to any other request, including in a query string, an attacker can get a logged-in user's browser to carry out any action that user is allowed to perform. For an administrator, that includes creating a new administrator.
No JavaScript, attacker-controlled page or form is needed, so the link can arrive by email or chat. Patchstack rates the flaw 8.8 out of 10; BleepingComputer considers it critical because of the level of access it gives. No CVE number had been assigned when both outlets reported.
Patchstack received the report from a researcher on 22 September and passed it to Elementor, which shipped the fix two days later. Neither outlet reports exploitation so far.
How many sites
Elementor has more than 10 million active installations. BleepingComputer, using WordPress.org statistics, says the two vulnerable versions are on up to 2 million sites; The Hacker News puts it at more than 2 million. Either way, the exposed group is large. BleepingComputer says the attack works where Editor Events is enabled; The Hacker News says the module ships with 4.3.0 and later.
Who is affected
Any business with a WordPress site built with Elementor, which covers a large share of small-business and agency-built sites. Anyone who administers such a site, in-house or at an agency, is the person an attacker needs to click.
What to do
- Check the Elementor version on every site you own or pay for. Anything on 4.3.0 or 4.3.1 should move to 4.3.2 or later now.
- If a site ran 4.3.0 or 4.3.1, review the list of administrator accounts and remove any you do not recognise, and check recent changes to plugins, themes and settings.
- Ask administrators to be wary of unexpected links while signed in to WordPress, and to use a separate browser profile for site administration.
- Some reviewers report editor problems with 4.3.x; if you roll back instead, go to 4.2.4 or earlier, not 4.3.0 or 4.3.1.
- If an agency maintains your site, ask it in writing which Elementor version is installed and when it was updated.
Sources
- WordPress.org plugin directory: Elementor Website Builder, changelog (read 2026-09-27) — 27 September 2026
- BleepingComputer: Elementor WordPress flaw lets attackers create admin accounts — 25 September 2026
- The Hacker News: Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link — 26 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.