A million sites, one Elementor add-on and an admin password reset
Elementor add-ons are everywhere, extending the most popular site builder. But popularity has a flip side: if such an add-on has a flaw, it immediately affects hundreds of thousands of sites.
What happened
Essential Addons for Elementor is one of the most installed plugins of its kind, over a million active installs. The flaw CVE-2023-32243 let an attacker reset any user's password (including the administrator's) without privileges, and then take over the account.
When an add-on is on a million sites, it pays for an attacker to write a single bot and unleash it on the whole internet. That is why such flaws are exploited en masse and fast.
Why it matters
A "small extension plugin" sounds harmless, but code is code, and the more add-ons, the greater the chance one of them has a hole. The blast radius depends on popularity, not on how "serious" the name sounds.
What to do
- Review your builder add-ons and remove the ones you do not use.
- Enable automatic updates for the plugins your site's look depends on.
- After a high-profile flaw, change administrator passwords and check whether there were reset attempts.
The rule repeats because it is true: fewer plugins, more urgent updates. That is the daily work of caring for a site, we will happily take it on.
Source: NVD, CVE-2023-32243.