Elementor Website Builder WordPress Plugin CSRF Vulnerability Disclosed
A cross-site request forgery (CSRF) vulnerability in the Elementor Website Builder WordPress plugin has been disclosed. The flaw, which carries a CVSS score of 8.8, could allow unauthenticated attackers to force an administrator to click a crafted link, resulting in the creation of a rogue administrator account and full site takeover. The vulnerability affects current versions of the plugin and remains without a CVE identifier. Exploitation requires administrator interaction, and no patch status has been specified in initial reports.






















