One Click Could Give Attackers Admin Access on Elementor WordPress Sites

The420.in Staff
4 Min Read

A security flaw in the widely used Elementor Website Builder for WordPress could expose logged-in administrators to one-click attacks that allow an attacker to create a new administrator account.

The affected versions, 4.3.0 and 4.3.1, are used on up to 2 million websites, according to WordPress.org statistics.

Which Elementor Versions Are Affected?

The vulnerability affects Elementor Website Builder versions 4.3.0 and 4.3.1. The flaw had not yet received an identifier at the time of the analysis.

Elementor is a popular WordPress plugin that allows users to create websites through a drag-and-drop interface. It is active on 10 million websites, while the two vulnerable versions are used on up to 2 million sites.

Older releases before version 4.3.0 do not contain the affected Editor Events proxy. However, some of those older versions contain other flaws that are already being actively exploited.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

How Does the Vulnerability Work?

Security firm Patchstack said the flaw stems from the Editor Events module checking the raw request URI for the elementor/v1/events/ path and bypassing WordPress REST nonce validation when that string is present.

Because the URI can also contain attacker-controlled query parameters, an attacker can append the path to requests targeting other REST endpoints.

This can trick a logged-in user into executing those requests with the privileges already available to their account.

Can Attackers Create an Admin Account?

According to Patchstack, the vulnerability can be abused in a one-click attack against a logged-in WordPress administrator.

A specially crafted link could cause the administrator’s account to perform a REST API action that it has permission to carry out. This could include creating a new administrator account controlled by the attacker.

“One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform,” Patchstack explained.

Does the Attack Need Malicious Code?

The attack does not require JavaScript, an attacker-controlled webpage or a submitted form, according to the security firm.

Instead, the malicious link can be sent directly to the intended target through an email, chat message or a comment posted on the website.

The danger is therefore tied to a logged-in user opening a specially prepared link while their WordPress account has sufficient privileges to perform the requested action.

What Should Elementor Users Do?

Users running the affected plugin versions are advised to upgrade to Elementor version 4.3.2 as soon as possible.

Remaining on versions 4.3.0 or 4.3.1 leaves websites exposed to the flaw described by Patchstack. Moving back to an older version is also not presented as a safe alternative because some earlier releases contain separate vulnerabilities that are already being actively exploited.

The420 Takeaway

The flaw shows how a single malicious link can become dangerous when opened by a logged-in administrator with powerful permissions. Elementor users should check their installed version and move to version 4.3.2 promptly rather than relying on an older release as a workaround.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected