Attackers can exploit a security flaw in the Elementor Website Builder WordPress plugin to create administrator accounts, potentially leading to full site takeover. Multiple outlets report that the issue is a cross-site request forgery (CSRF) vulnerability that may allow an unauthenticated attacker to perform the account-creation action.

Reporting adds that the flaw requires specific conditions to be successful. One account notes that the attack depends on an admin interacting with a crafted link, after which the forged request can be carried out. The vulnerability is described as high severity, with one source citing a CVSS score of 8.8/10.0, and it has not yet been assigned a CVE identifier according to the coverage.

Across the reports, the main difference is emphasis: one focuses on the technical mechanism—CSRF enabling rogue administrator account creation by an unauthenticated party—while another highlights the practical exploitation flow involving an administrator click. Together, they indicate a risk of account provisioning and subsequent control if the vulnerable plugin version is present and the interaction conditions are met.