Security

A million sites, one Elementor add-on and an admin password reset

A million sites, one Elementor add-on and an admin password reset

Elementor add-ons are everywhere, extending the most popular site builder. But popularity has a flip side: if such an add-on has a flaw, it immediately affects hundreds of thousands of sites.

What happened

Essential Addons for Elementor is one of the most installed plugins of its kind, over a million active installs. The flaw CVE-2023-32243 let an attacker reset any user's password (including the administrator's) without privileges, and then take over the account.

When an add-on is on a million sites, it pays for an attacker to write a single bot and unleash it on the whole internet. That is why such flaws are exploited en masse and fast.

Why it matters

A "small extension plugin" sounds harmless, but code is code, and the more add-ons, the greater the chance one of them has a hole. The blast radius depends on popularity, not on how "serious" the name sounds.

What to do

  • Review your builder add-ons and remove the ones you do not use.
  • Enable automatic updates for the plugins your site's look depends on.
  • After a high-profile flaw, change administrator passwords and check whether there were reset attempts.

The rule repeats because it is true: fewer plugins, more urgent updates. That is the daily work of caring for a site, we will happily take it on.

Source: NVD, CVE-2023-32243.

Related articles

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.