Elementor WordPress Plugin Flaw Could Let Attackers Create Administrator Accounts
A cross-site request forgery (CSRF) vulnerability in the Elementor Website Builder plugin for WordPress could allow an unauthenticated attacker to create a new administrator account under their control.
Elementor CSRF flaw affects up to 2 million sites
Elementor is a popular WordPress plugin used by 10 million websites. It allows users to build and customize websites with a drag-and-drop interface.
The vulnerability affects only Elementor versions 4.3.0 and 4.3.1. The flaw does not yet have a vulnerability identifier. According to WordPress.org statistics, up to 2 million sites use one of the affected versions.
Security firm Patchstack reported the issue to Elementor on September 22 after receiving it from bug hunter Saggre. Elementor released a fix two days later in version 4.3.2.
How the Elementor vulnerability works
An attacker could exploit the CSRF flaw by tricking a logged-in WordPress administrator into opening a malicious link. The link causes the victim’s authenticated session to perform REST API actions allowed for that account.
According to Patchstack’s analysis, the flaw is caused by Elementor’s Editor Events module checking the raw request URI for the elementor/v1/events/ path. When that string is present, the request can bypass WordPress REST nonce validation.
The URI also accepts attacker-controlled query parameters. This allows an attacker to append the path to requests targeting other REST endpoints and trick logged-in users into performing actions with their existing privileges.
Patchstack said the flaw could be exploited in a one-click attack against a logged-in administrator to create a new administrator account controlled by the attacker.
“A single link opened by a logged-in WordPress user allows that user to perform any REST API action that their account is allowed to perform.”
The security firm said the attack does not require JavaScript, an attacker-controlled web page, or a submitted form. An attacker could deliver the malicious link through email, a chat message, or a comment on the site.
Update Elementor to version 4.3.2
WordPress site owners using Elementor 4.3.0 or 4.3.1 should upgrade to version 4.3.2 as soon as possible to prevent attackers from triggering the vulnerability through query strings.
Versions released before Elementor 4.3.0 do not include the affected Editor Events proxies. However, older versions are vulnerable to other flaws, some of which are already being actively exploited.
To check the installed version, open the WordPress dashboard and navigate to the installed plugins section. Update Elementor if version 4.3.0 or 4.3.1 is installed.
View Elementor version usage statistics on WordPress.org.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



