Security News Elementor WordPress flaw lets attackers create admin accounts BleepingComputer Daniel Bender 25 Sep 2026 Share A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts.