Unidentified threat actors are actively exploiting a recently patched security flaw in the Elementor Pro page builder plugin for WordPress.
The vulnerability, described as a case of broken access control, affects versions 3.11.6 and earlier. It was fixed by the plugin maintainers in version 3.11.7.
“Improved security code enforcement in WooCommerce components,” the Tel Aviv-based company said in its release notes. The premium plugin is estimated to be in use on more than 12 million websites.
Successful exploitation of this high-severity vulnerability allows an authenticated attacker to fully take over a WordPress site with WooCommerce enabled.
“This makes it possible for a malicious user to enable the registration page (if disabled) and set the default user role to administrator, so that they can immediately create an account with administrator privileges,” Patchstack said in an advisory dated 30/2023.
“From there, they could redirect the site to another malicious domain, or upload a malicious plugin or backdoor to exploit the site further.”

Credited with discovering and reporting the vulnerability in 2023 is NinTechNet security researcher Jerome Bruandet.
Patchstack further notes that the vulnerability is being exploited in the wild from a number of IP addresses attempting to upload arbitrary PHP and ZIP archive files.
Users of the Elementor Pro plugin are advised to update to 3.11.7 or 3.12.0, the latest versions, as soon as possible to reduce potential threats.