Elementor is vulnerable to Cross-Site Request Forgery (CSRF)
88
High Risk
Events_Proxy_REST_API::bypass_nonce_check_for_own_routes treats any request URI containing elementor/v1/events/ as one of its own routes and returns authentication success before WordPress verifies the REST nonce. is_own_route_request searches the raw URI, which includes attacker-controlled query parameters, so an unauthenticated attacker can append that marker to an unrelated REST request and induce a logged-in user to execute it with their existing permissions. If an administrator opens a crafted link, the attacker can create a new administrator account and take over the site. The fix checks the resolved REST route instead of the raw URI and requires the Elementor events namespace at the start of the route.
You are affected if you are using a version that falls within the vulnerable range and a logged-in WordPress user can be induced to open an attacker-crafted link.
Elementor is vulnerable to Cross-Site Request Forgery (CSRF) in versions 4.3.0 - 4.3.1.
Upgrade the Elementor library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.