Summary
A critical vulnerability in Elementor Pro, the WordPress page builder plugin installed on more than 8 million sites, allows unauthenticated remote attackers to create administrator accounts without any credentials. CVE-2026-52917 is rated CVSS 9.8 and affects all Elementor Pro versions prior to 3.25.3. Active exploitation has been observed by Wordfence and Patchstack. Elementor has released version 3.25.3 and all users should update immediately.
Timeline
| Date | Event |
|---|---|
| September 2026 | CVE-2026-52917 discovered; active exploitation observed before patch |
| Sep 24, 2026 | Elementor Pro 3.25.3 released; BleepingComputer reports exploitation |
| Sep 25, 2026 | TTO-2026-0925-169 published; exploitation ongoing against unpatched sites |
What Happened
CVE-2026-52917 exists in Elementor Pro’s form submission handler. Elementor Pro forms include a “create user” action for registering WordPress users on submission. A permission validation flaw allows this handler to be called without authentication and without the action being configured in any published form — the attack works against any site with Elementor Pro installed, regardless of whether forms are used for registration.
An attacker sends a crafted POST request to the form submission endpoint specifying the create-user action with a username, email, password, and role parameter set to “administrator.” The handler creates the account without verifying request legitimacy or the requester’s permissions. Sites running Elementor Pro should update to 3.25.3 immediately, audit administrator account lists for unexpected additions, and review recent authentication logs.
Domain Intelligence
elementor.com — 62.54
elementor.com scores in the low-trust range at 62.54. Elementor is the vendor of the affected plugin and the party that released the patch. One threat intelligence source has flagged elementor.com but the observation has not been independently corroborated.
The Trust Observatory · thetrustobservatory.com · September 25, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026