:

ELEMENTOR PLUGIN FLAW LETS ATTACKERS CREATE ADMIN ACCOUNTS

INDUSTRY DESK■ 1 MIN READ
FRI, SEP 25, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A cross-site request forgery (CSRF) vulnerability in the popular Elementor WordPress plugin could allow unauthenticated attackers to create administrator accounts on affected sites.

The vulnerability exists in Elementor, a widely-used page builder plugin for WordPress with millions of installations. By exploiting the CSRF flaw, attackers can bypass authentication mechanisms and gain full administrative access to compromised websites without requiring valid credentials. CSRF vulnerabilities work by tricking authenticated users into performing unintended actions. In this case, an attacker could craft a malicious link or embed code that, when accessed by a site administrator, creates a new admin account under the attacker's control. The flaw affects site security at a critical level, granting attackers the same permissions as legitimate administrators. This includes access to sensitive data, modification of site content, installation of malicious plugins, and potential platform-wide compromise. Elementor users should update to the latest patched version immediately. Website administrators should also review user accounts for unauthorized access and implement security best practices including regular backups and access monitoring.

■ SOURCES

► Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about active exploits targeting critical vulnerabilities in SharePoint, WSO2, and Adobe Commerce. Attackers are actively leveraging these flaws in real-world attacks.

2H AGO— Security Desk

Multiple Supabase customers have inadvertently exposed sensitive user data online due to misconfiguration and inadequate security settings. The incidents underscore risks inherent in rapidly deployed AI-generated and minimally-configured applications.

2H AGO— Industry Desk

File transfer platform Kiteworks has urged customers to shut down their servers after receiving a credible threat of an imminent cyberattack from law enforcement.

4H AGO— Security Desk

Cryptocurrency exchange Bitget disclosed a breach of its hot and warm wallets, with hackers stealing $351.6 million. The attack is attributed to suspected North Korean threat actors.

6H AGO— Security Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.