WordPress hosts and site operators should make sure Elementor installs have moved past two short-lived vulnerable releases after Patchstack disclosed a high-severity cross-site request forgery flaw in the page builder.
Patchstack said Elementor Website Builder versions 4.3.0 and 4.3.1 disabled WordPress core’s CSRF protection for cookie-authenticated REST API requests when a request URI contained the string elementor/v1/events/. Because an attacker could place that string in a query parameter, Patchstack said a crafted link could cause a logged-in WordPress user to perform REST API actions allowed by that user’s account.
The practical risk is highest for administrators. On a stock WordPress installation, Patchstack said an administrator who opened a malicious link could be made to create another administrator account for the attacker. The security firm rated the issue CVSS 8.8 and said the link did not need JavaScript, a submitted form, or an attacker-controlled web page.
Elementor fixed the issue in version 4.3.2 by checking the resolved REST route instead of the raw request URI, according to the advisory. Hosting providers that manage WordPress fleets should treat the disclosure as a reminder to audit plugin auto-update coverage, especially for page builders installed across many shared-hosting and managed WordPress accounts.
For site owners, the immediate action is straightforward: update Elementor, confirm the installed version is not 4.3.0 or 4.3.1, and review administrator accounts for unexpected additions if an affected version was active on a production site.
Source: Patchstack security advisory.
