BoletimSec•September 28, 2026•🇵🇹Translated from Portuguese

CSRF Flaw in Elementor Allows Admin Account Creation on Over 2 Million WordPress Sites

A CSRF vulnerability in the Elementor page builder plugin affects more than 2 million WordPress sites, allowing attackers to create administrator accounts on vulnerable installations.

The flaw impacts versions 4.3.0 and 4.3.1, which together account for over 2 million active installations. Elementor itself is present in more than 10 million WordPress sites. The vulnerability received a CVSS score of 8.8, placing it in the high severity range. At the time of public disclosure on September 26, no CVE identifier had been assigned.

The root cause lies in the Editor Events module, which fails to properly enforce CSRF protections on cookie-authenticated requests to the WordPress REST API. By appending the parameter elementor/v1/events/ as a query string, any REST request bypasses the plugin's verification checks. This occurs because the browser automatically includes session cookies with every request, and the plugin does not confirm whether the request originated from the legitimate site dashboard.

The attack requires no special form, JavaScript, or attacker-controlled webpage. A simple link, such as an anchor in an email or instant message, is sufficient. When a logged-in administrator clicks the link, the browser sends an authenticated request that, on a default installation, results in the creation of a second administrator account.

Beyond the plugin itself, the flaw exposes the entire surface of the WordPress REST API, including core endpoints and routes provided by other plugins installed on the same site. The issue was discovered by researcher Saggre and resolved through responsible disclosure. The fix was released in version 4.3.2. Site owners running the affected versions should update immediately. At the time of analysis, no public evidence of active exploitation had been recorded.

Related articles

Hispasec•Vulnerabilities & Exploits

CISA Sets September 30 Deadline for Federal Agencies to Patch Actively Exploited Citrix NetScaler Zero-Days

CISA has ordered U.S. federal agencies to apply patches by September 30 for two actively exploited zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, enable unauthenticated remote code execution under default configurations and affect systems commonly exposed to the internet. CVE-2026-88771 allows remote code execution without authentication on NetScaler ADC and Gateway, while CVE-2026-88772 can trigger remote code execution or denial of service via a memory overflow when DTLS is enabled on VPN vServers. Citrix has released fixes for versions 14.1 and 13.1, including FIPS and NDcPP builds, with minimum required builds of 14.1-73.37 and 13.1-64.23. The advisory also covers six additional vulnerabilities from CVE-2026-88773 to CVE-2026-88778 involving HTTP request smuggling and TCP ISN prediction issues. Unsupported branches NetScaler 12.1 and 13.0 receive no patches, requiring immediate migration. Organizations are advised to inventory instances, check for compromise indicators before patching, and preserve forensic evidence.

BoletimSec•Vulnerabilities & Exploits

Mandiant Uncovers WAF Bypass Campaign Exploiting Critical Oracle PeopleSoft CVE-2026-35273

Mandiant has identified an active campaign abusing CVE-2026-35273, a critical unauthenticated remote code execution flaw in Oracle PeopleSoft's Environment Management Hub (PSEMHUB). Attackers bypass web application firewalls by replacing the literal path /PSEMHUB/ with /%50SEMHUB/, exploiting the fact that many WAF rules inspect the URL before decoding while the PeopleSoft application server decodes it afterward. The exploitation chain relies on Java object deserialization via POST requests to /%50SEMHUB/hub, allowing deployment of two distinct JSP web shells. The group then establishes persistence with a trojanized installer that drops the SIDEEYE backdoor along with Neo-reGeorg and MeshAgent. Activity attributed to UNC6240, linked to ShinyHunters, began as a zero-day against educational institutions in June 2026 and has since expanded to higher education, technology, healthcare, agriculture, transportation, and government sectors.

Habr•Vulnerabilities & Exploits

Dissecting CVE-2026-83557 in jackson-databind: Why Not Every CVE Requires Immediate Panic

A detailed analysis of CVE-2026-83557 reveals that the vulnerability in jackson-databind affects only a narrow set of configurations involving polymorphic deserialization with the Comparable base type. The flaw stems from an incomplete denylist in DefaultBaseTypeLimitingValidator, which overlooks java.lang.Comparable when the MapperFeature.BLOCK_UNSAFE_POLYMORPHIC_BASE_TYPES flag is explicitly enabled. Researchers constructed working proof-of-concept exploits showing that an attacker can instantiate classes such as java.io.File, but only when the property is declared as Comparable<?> and the protective flag is active. The issue impacts versions 2.11 through 2.22.1, yet the CVSS score of 5.6 reflects its moderate real-world risk because most applications lack the required Comparable-typed polymorphic fields. Patching introduces its own trade-off by blocking legitimate Comparable subclasses, forcing developers to implement custom BasicPolymorphicTypeValidator allowlists. The case highlights how dependency scanners often flag CVEs without considering application-specific configuration and DTO structures.

Security NEXT•Vulnerabilities & Exploits

Multiple Critical Vulnerabilities Found in Citrix NetScaler ADC and Gateway, Two Actively Exploited

Cloud Software Group disclosed eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway products on September 27, 2026. Two of the issues, CVE-2026-88771 and CVE-2026-88772, have already been confirmed as exploited in the wild, prompting urgent remediation advice. CVE-2026-88771 stems from insufficient input validation and allows unauthenticated remote code execution across all default configurations. CVE-2026-88772 involves a memory overflow that can lead to code execution or denial of service when DTLS is enabled, which occurs by default on VPN vServers. The remaining six vulnerabilities cover code execution, denial of service, and HTTP request smuggling risks, with the advisory rated Critical overall. Organizations are urged to apply patches immediately and investigate potential breaches.