◈ Cii.中国 · 天地一体信息中心 九霄观澜 · 宇宙观察 · RSS

Elementor CSRF漏洞允许攻击者在管理员点击精心制作的链接后接管网站

暗流情报2026-09-26 · 来源:开源情报·The Hacker News
Elementor CSRF漏洞允许攻击者在管理员点击精心制作的链接后接管网站

有关Elementor Website Builder WordPress插件中一个高严重性安全漏洞的详细信息,该漏洞可能被未经身份验证的攻击者利用来创建流氓管理员帐户

原文标题:Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

信源:The Hacker News | 阅读原文

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery

—— 开源情报自动采集 · 综合