Elementor WordPress flaw lets attackers create admin accounts
Summary
A cross-site request forgery (CSRF) vulnerability has been discovered in the Elementor plugin for WordPress. This flaw allows unauthenticated attackers to create administrator accounts on affected websites.
IFF Assessment
The vulnerability allows attackers to gain administrative access to WordPress sites, which is detrimental to defenders.
Severity
This vulnerability is rated as Critical (9.8) due to its high impact (complete administrative control of a WordPress site) and ease of exploitability via a CSRF attack, which can be triggered remotely without authentication.
Defender Context
Defenders should prioritize updating the Elementor plugin to the latest version to mitigate this critical vulnerability. This highlights the ongoing risk posed by popular WordPress plugins and the need for regular patching and security audits.