SECURITY·중요도 9·2026. 09. 26.·The Hacker News

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

── KO ──────────────────

Elementor 플러그인에서 관리자 계정을 탈취할 수 있는 보안 취약점이 발견됨.

WordPress의 Elementor 웹사이트 빌더 플러그인에서 심각한 CSRF 보안 취약점이 발견됐다. 이로 인해 인증되지 않은 공격자가 악성 관리자 계정을 생성하여 웹사이트를 장악할 수 있다. 이 취약점은 아직 CVE 식별자가 할당되지 않았으며, CVSS 점수는 8.8로 매우 높다.


── EN ──────────────────

A CSRF security flaw in Elementor plugin allows attackers to take over sites.

A serious CSRF security vulnerability has been found in the Elementor website builder plugin for WordPress. This flaw allows unauthenticated attackers to create rogue administrator accounts and take control of websites. The vulnerability has not yet been assigned a CVE identifier and carries a high CVSS score of 8.8.

원문 보기 →목록으로