TTO-2026-0925-169 · September 25, 2026 Active ExploitationCritical

Critical Elementor Pro WordPress Plugin Flaw Allows Unauthenticated Attackers to Create Administrator Accounts

elementor.comCVE-2026-52917 CVSS 9.8Elementor Pro — 8M+ installationsUnauthenticated admin account creationActive exploitation observedPatched in 3.25.3

Summary

A critical vulnerability in Elementor Pro, the WordPress page builder plugin installed on more than 8 million sites, allows unauthenticated remote attackers to create administrator accounts without any credentials. CVE-2026-52917 is rated CVSS 9.8 and affects all Elementor Pro versions prior to 3.25.3. Active exploitation has been observed by Wordfence and Patchstack. Elementor has released version 3.25.3 and all users should update immediately.

Timeline

DateEvent
September 2026CVE-2026-52917 discovered; active exploitation observed before patch
Sep 24, 2026Elementor Pro 3.25.3 released; BleepingComputer reports exploitation
Sep 25, 2026TTO-2026-0925-169 published; exploitation ongoing against unpatched sites

What Happened

CVE-2026-52917 exists in Elementor Pro’s form submission handler. Elementor Pro forms include a “create user” action for registering WordPress users on submission. A permission validation flaw allows this handler to be called without authentication and without the action being configured in any published form — the attack works against any site with Elementor Pro installed, regardless of whether forms are used for registration.

An attacker sends a crafted POST request to the form submission endpoint specifying the create-user action with a username, email, password, and role parameter set to “administrator.” The handler creates the account without verifying request legitimacy or the requester’s permissions. Sites running Elementor Pro should update to 3.25.3 immediately, audit administrator account lists for unexpected additions, and review recent authentication logs.

Domain Intelligence

elementor.com — 62.54

elementor.com scores in the low-trust range at 62.54. Elementor is the vendor of the affected plugin and the party that released the patch. One threat intelligence source has flagged elementor.com but the observation has not been independently corroborated.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 25, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026