← volver al portal

Elementor WordPress Plugin Flaw Allows Attackers to Create Administrator Accounts

A cross-site request forgery (CSRF) vulnerability was discovered in the Elementor plugin for WordPress that could allow unauthenticated attackers to…

If you manage WordPress sites running the Elementor plugin, update to the patched version immediately. Check for suspicious administrator accounts created recently. Consider implementing additional CSRF protections at firewall or security plugin level while you confirm the update is applied.