• Home
  • News
    • AI News
    • Crypto News
  • A.I
  • Smartphones
  • Tech Guides
    • Apps
    • Mac
    • Social Media
    • Tips and Tricks
Tech Tout
No Result
View All Result
  • Home
  • News
    • AI News
    • Crypto News
  • A.I
  • Smartphones
  • Tech Guides
    • Apps
    • Mac
    • Social Media
    • Tips and Tricks
Tech Tout
Google News
No Result
View All Result
Tech Tout
No Result
View All Result
Home News Hacker News

Millions of WordPress sites at risk from Hackers exploiting Elementor Pro vulnerability

Hackers actively exploiting flaw that allows complete takeover of vulnerable WordPress sites using WooCommerce.

Geek Desk by Geek Desk
April 1, 2023
in Hacker News, Security News
A laptop with WordPress logo placed on a surface

Image via Unsplash

141
SHARES
1.3k
VIEWS
Share on FacebookShare on Twitter
Summary: Hackers are exploiting a security vulnerability in the Elementor Pro website builder plugin for WordPress, which is estimated to be used on over 12 million sites. The flaw allows attackers to create an account with administrator privileges and potentially take over a WordPress site. Users are advised to update to the latest version of the plugin to mitigate the risk of potential threats.

Unknown attackers are exploiting a recently patched security vulnerability in the Elementor Pro website builder plugin for WordPress, putting millions of sites at risk. The flaw affects versions 3.11.6 and earlier and was fixed by the plugin maintainers in version 3.11.7. The vulnerability is a case of broken access control, allowing an authenticated attacker to take over a WordPress site that has WooCommerce enabled, giving them administrator privileges. Users of the plugin are urged to update to version 3.11.7 or 3.12.0 as soon as possible.

settings change wordpress sites being actively exploited thanks to plugins 2025

NinTechNet security researcher Jerome Bruandet discovered and reported the vulnerability on March 18, 2023. Patchstack has noted that the flaw is being exploited in the wild from several IP addresses, with attackers attempting to upload arbitrary PHP and ZIP archive files. If exploited, a malicious user could turn on the registration page (if disabled) and set the default user role to administrator. This would allow them to create an account that instantly has the administrator privileges. They could then redirect the site to another malicious domain or upload a malicious plugin or backdoor to further exploit the site.

leak wordpress sites being actively exploited thanks to plugins 2025

This is not the first time a vulnerability has been discovered in an Elementor plugin. The Essential Addons for Elementor plugin was found to contain a critical vulnerability that could result in the execution of arbitrary code on compromised websites. WordPress also issued auto-updates to remediate another critical bug in the WooCommerce Payments plugin that allowed unauthenticated attackers to gain administrator access to vulnerable sites.

Tags: ElementorWordPress
Share56Tweet35Pin15
Previous Post

Ford F-150 Lightning now starts at a higher price of $20K

Next Post

Breaking News: Twitter logo changed to DogeCoin’s Dog face

Geek Desk

Geek Desk

The post is written and edited by a member of TechTout's geek desk. The team members are comprised of tech geeks, and enthusiasts, who are passionate about technology and helping people with technology guides.

Related Posts

A black and white photo of a person wearing anonymous mask

Major security vulnerabilities found in Google Pixel, Samsung, and Vivo phones

March 31, 2023
Twitter with SMS 2FA won't be same anymore

Last day to keep Twitter’s SMS 2FA authentication

March 20, 2023
Next Post
Doge dog with elon musk a design of manipulated image of them going to moon

Breaking News: Twitter logo changed to DogeCoin's Dog face

A photo of DogeCoin with golden pearls

Elon Musk's latest move sends DogeCoin soaring: Will it finally reach $1?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

three × 1 =

Trending

  • Trending
  • Comments
  • Latest
username doesn't belong error on instagram fixed

How to fix “Username you entered doesn’t belong to an account” error on Instagram

November 1, 2023
Instagram dark mode guide

How to enable dark mode on Instagram 2025

October 29, 2023
Best metal body laptops on Amazon

Best Metal Gaming Laptops 2025

May 21, 2023
Most popular Linux distros in 2023

25 popular Linux distros 2025

August 23, 2023
A photo of a person using Instagram on iPhone, showing Instagram stories decorations

Instagram story decoration Ideas in 2025

July 30, 2023
Best iPhones browsers

10 Best Browsers for iPhone in 2025

November 1, 2023
Lifestyle apps for IOs and Android users

Top 9 lifestyle apps that will improve the quality of your life in 2025

October 27, 2023
username doesn't belong error on instagram fixed

How to fix “Username you entered doesn’t belong to an account” error on Instagram

8
Disable Facebook Messenger channel invites

🚫 Disable Channel invites on Facebook Messenger

3
Meta announces a verified badge subscription for Instagram and Facebook

Mark Zuckerberg announces Meta Verified subscription, like Twitter Blue

2
high angle photo of a mobile

11 Latest Instagram Tips and Tricks 2025

1
ChatGPT 3D logo

Yes, ChatGPT is down globally

1
instagram story photos

How to add multiple photos on your Instagram story

0
A photo of Snapchat ghost wearing a black cap for how to get Snapstreaks back

How to get your Snapstreaks back after losing them

0
A photo of newly released MacBook Air 2024 with M3 Apple Silicon chipset

Apple announces MacBook Air with M3 chip

March 5, 2024
ChatGPT logo in green

ChatGPT can now remember our conversations

February 14, 2024
Twitter is down globally

Yes, Twitter is down, again

December 21, 2023
Twitter Verified 3D artwork

X blue, gold tick not showing: How to fix it?

December 16, 2023
Twitter error page

X’s latest outage is broken t.co short links (Update: It’s working now)

December 14, 2023
Elon Musk Twitter followers as of March 31st

ChatGPT makes Elon Musk angry

December 10, 2023
Showbox alternatives, article's featured image

9+ best Showbox alternatives to watch free movies

December 6, 2023
A photo of newly released MacBook Air 2024 with M3 Apple Silicon chipset
Mac News

Apple announces MacBook Air with M3 chip

by Muhammad Abdullah
March 5, 2024
0

Apple took the wraps off its highly anticipated new MacBook Air models today, unveiling updated 13-inch and 15-inch versions powered...

Read more
ChatGPT logo in green

ChatGPT can now remember our conversations

February 14, 2024
Twitter is down globally

Yes, Twitter is down, again

December 21, 2023
Twitter Verified 3D artwork

X blue, gold tick not showing: How to fix it?

December 16, 2023
Twitter error page

X’s latest outage is broken t.co short links (Update: It’s working now)

December 14, 2023

TechTout

TechTout covers the latest news on tech, car tech, business, smartphones, gadgets, and the latest product reviews including how-to guides on Windows, Mac, Android, iOS, Linux, and more.

TechTout covers the latest news on tech, car tech, business, smartphones, gadgets, and the latest product reviews including how-to guides on Windows, Mac, Android, iOS, Linux, and more.

Top Categories

  • Home
  • News
    • AI News
    • Crypto News
  • A.I
  • Smartphones
  • Tech Guides
    • Apps
    • Mac
    • Social Media
    • Tips and Tricks

Pages

  • About us
  • Contact Us
  • Disclaimers
  • Disclosure
  • Home
  • Newsletter
  • Our Experts
  • Privacy Policy
  • Terms and Conditions
  • Write for us

Recent Posts

  • Apple announces MacBook Air with M3 chip
  • ChatGPT can now remember our conversations
  • Yes, Twitter is down, again
  • X blue, gold tick not showing: How to fix it?
  • X’s latest outage is broken t.co short links (Update: It’s working now)

© 2025 TechTout - A GameBird Media site - All Rights Reserved.

No Result
View All Result
  • Home
  • About us
  • Contact us
  • Write for us
  • Disclaimers
  • Privacy Policy
  • Disclosure
  • Terms and Conditions

© 2025 TechTout - A GameBird Media site - All Rights Reserved.