A cross-site request forgery vulnerability has been identified in Elementor, a widely used WordPress page builder plugin. According to BleepingComputer, the flaw could allow an attacker who is not logged in to create administrator accounts on affected sites.
Because this is a CSRF issue, exploitation typically requires an already-authenticated administrator to perform an unintended action. An attacker would likely need to convince that admin to visit a malicious page or click a crafted link, which could then submit a forged request to the WordPress site using the admin's session.
The potential impact is severe: gaining an admin account means taking control of the site, including its content, users, and plugins. Site owners running Elementor should watch for security updates from the plugin team and apply them promptly to reduce exposure.