Skip to main content

Tag: elementor

2 articles

Laptop screen displays WordPress admin dashboard on a clean office desk.

Elementor WordPress Plugin Exploited to Create Admin Accounts

A critical vulnerability in the popular Elementor WordPress Plugin has put up to 2 million sites at risk of admin account takeovers, with a single click on a malicious link potentially allowing hackers to gain control. This alarming exploit highlights the importance of updating to secure versions and exercising caution when clicking on links.

Analyst 207
WordPress admin dashboard on laptop with blurred promotional banner feed.

WordPress Plugins Targeted by Rogue Feed Exploits

Hackers have found a sneaky way to exploit WordPress plugins, using a promotional banner feed to plant rogue administrator accounts and webshells on live sites - all without modifying a single plugin file. The attack, traced back to an unescaped field in a banner notice, has already hit seven plugins from a popular Elementor add-on vendor.

Analyst 207