Home / Sep 27, 2026 / Story
0
#9 The Hacker News general September 26, 2026 at 09:55 UTC

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

By [email protected] (The Hacker News)

AI Summary

A high-severity CSRF vulnerability (CVSS 8.8) in the Elementor Website Builder WordPress plugin — which has tens of millions of installs — allows unauthenticated attackers to create rogue administrator accounts if an existing admin clicks a crafted link. No CVE has been assigned yet, and admins should verify plugin versions and apply available patches immediately.

Relevance score: 76.0/100

# More from September 27