Skip to content

person

Saggre

Security researcher and bug hunter who publishes under the alias Saggre.

Current clusters

security3 publishers

One clicked link creates an attacker admin on Elementor 4.3.0 and 4.3.1

Elementor 4.3.0 and 4.3.1 carry a CSRF flaw that lets an attacker turn one link, clicked by a logged-in admin, into a rogue administrator account. Version 4.3.2, released this week, closes the query-string bypass.

Perspective Coverage

3 publishers
Builder
Builder 38%
Operator
Operator 55%
Investor
Investor 7%

Reality

Evidence72
Adoption60
Hype gap+10
Incentives30
Confidence74