# Elementor fixes WordPress flaw that could let attackers create admin accounts

_Published Friday, September 25, 2026 at 5:07 PM EDT · Security · Latest · Tier 2 — Notable_

![Elementor fixes WordPress flaw that could let attackers create admin accounts — Primary](https://www.bleepstatic.com/content/hl-images/2023/12/07/back-2.jpg)

Elementor has released version 4.3.2 of its WordPress plugin to fix a flaw that could let an attacker create an administrator account. The attack requires a logged-in administrator to open a malicious link. That action can make the administrator's session send an authorized request to the site.

The flaw affects versions 4.3.0 and 4.3.1, which WordPress.org statistics indicate are used by up to 2 million sites. Security firm Patchstack says the plugin could be tricked into skipping a check intended to confirm that the administrator authorized the request. Earlier versions lack the affected component but have other vulnerabilities.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/)

---
Canonical: https://techandbusiness.org/newswire/fFXDNoGH-ddRM-EreCv9L4
Published: 2026-09-25T21:07:26.249Z
Story chronology: 2026-09-25T18:13:33.000Z
Retrieved: 2026-09-25T23:03:35.846Z
Publisher: Tech & Business (techandbusiness.org)
