Elementor flaw: one link can hand over your WordPress site
A dangerous vulnerability has been found in Elementor, a popular website builder for WordPress. All it takes is for a site administrator who is logged in to the dashboard to open a specially crafted link — and a new administrator controlled by the attacker appears on the site. A fix is already out: version 4.3.2.
Who is affected
Elementor runs on more than 10 million websites. Only versions 4.3.0 and 4.3.1 are vulnerable — about 2 million sites, according to WordPress.org statistics. If your company website is built on WordPress, there is a good chance it uses Elementor.
How the attack works, in plain words
The attacker sends an ordinary-looking link — in an email, a messenger or a comment on the site. If it is opened by someone who is logged in to the site dashboard at that moment, the site carries out a command on their behalf, such as "create a new administrator". No password guessing, no hosting breach, and no forms or scripts on the attacker's side are needed.
With administrator rights, anything can be done to the site: contact and bank details can be swapped, malicious code planted, or spam sent in the company's name.
The flaw was found by a researcher known as Saggre. Patchstack reported it to the developers on September 22, and version 4.3.2 with the fix was released two days later.
What to do today
- Log in to WordPress → Plugins and check the Elementor version.
- If it is 4.3.0 or 4.3.1, update to the latest version. Versions older than 4.3.0 are not affected by this flaw, but they have other known vulnerabilities, so update anyway.
- Open Users and filter by the Administrator role. An account you don't recognise means you should delete it immediately, change all administrator passwords and have the whole site checked.
- Turn on automatic updates for plugins: the plugin list has an "Enable auto-updates" link.
- Until you update, don't open unfamiliar links while logged in to the site dashboard.
If a contractor built your site
Ask them three questions: who updates the plugins and how often, is there a recent backup of the site, and who currently has administrator access. If any of these has no clear answer, nobody is really looking after the site.
Not sure which version you have? Send your website address to info@nextgenit.com.cy — we will check it for free using public data.
Sources: BleepingComputer, The Hacker News.