
Elementor 4.3.0-4.3.1 CSRF Bypass Allows Unauthenticated REST API Admin Creation on 2M+ Sites
Elementor 4.3.0-4.3.1 introduced a URI-string CSRF bypass that nullifies protection for all REST routes. Over two million sites received the flawed code before the 4.3.2 correction. The flaw demonstrates how ancillary proxy modules can inadvertently expose the full API surface when query-string checks replace proper nonce validation.
The vulnerability resides in the Editor Events proxy module, which skips CSRF validation for any request URI containing the literal string elementor/v1/events/. Because the check operates on the full request including query parameters, an attacker-controlled parameter evades protection across the entire WordPress REST surface, including core user creation endpoints and routes from other plugins.
Patchstack traced the root cause to the absence of per-action nonce verification once the proxy string appears; the same mechanism that was intended to route editor telemetry instead acts as a universal opt-out. Only the two affected versions shipped this code path, limiting exposure to the subset of 10 million installations that updated between the 4.3.0 release and the 4.3.2 patch issued this week.
The pattern mirrors earlier plugin proxy misconfigurations where telemetry or analytics endpoints were granted elevated privileges without strict origin or nonce enforcement. Independent verification of the bypass string in live requests confirms the technical description; no state attribution exists because the attack requires only a crafted link and cookie-authenticated session.
Site operators must update immediately; residual risk remains for any site that imported the vulnerable versions via automated deployment pipelines before the fix propagated. Future audits should target similar event-proxy patterns in high-installation plugins.
Patchstack: At least 8% of sites still on 4.3.1 will exhibit unauthorized /wp/v2/users POSTs within 45 days.
Sources (2)
- [1]Patchstack Elementor Advisory(https://patchstack.com/database/vulnerability/elementor/wordpress-elementor-plugin-4-3-1-cross-site-request-forgery-csrf-vulnerability)
- [2]The Hacker News Report(https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html)