Tag: elementor
2 articles

Elementor WordPress Plugin Exploited to Create Admin Accounts
A critical vulnerability in the popular Elementor WordPress Plugin has put up to 2 million sites at risk of admin account takeovers, with a single click on a malicious link potentially allowing hackers to gain control. This alarming exploit highlights the importance of updating to secure versions and exercising caution when clicking on links.

WordPress Plugins Targeted by Rogue Feed Exploits
Hackers have found a sneaky way to exploit WordPress plugins, using a promotional banner feed to plant rogue administrator accounts and webshells on live sites - all without modifying a single plugin file. The attack, traced back to an unescaped field in a banner notice, has already hit seven plugins from a popular Elementor add-on vendor.