Insights
One click, one new administrator: the Elementor CSRF flaw explained
A flaw in Elementor 4.3.0 and 4.3.1 lets anyone who can get a WordPress administrator to click a link create themselves an administrator account. No JavaScript, no form, no exploit kit: a plain link. Around two million sites were exposed. Here is how it works, why it is worse than it sounds, what to do this morning, and the Wazuh rules our SOC is using to see it.
Peter Bassill10 min read · 8 reads