CyberSecurity News
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
AI summary
A high-severity security flaw has been discovered in the Elementor Website Builder WordPress plugin, which could allow an unauthenticated attacker to create rogue administrator accounts and take control of a site. The vulnerability is a cross-site request forgery flaw that can be exploited when an admin clicks a crafted link. It has a CVSS score of 8.8 out of 10.0, indicating a significant level of severity. The flaw has not been assigned a CVE identifier yet. The vulnerability only affects certain versions of the plugin, although the specific versions are not specified.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

