Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Gaming
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Journalist Application
    • Contact Us
Reading: Hackers Exploit Vulnerability In The Elementor Pro WordPress Plugin
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > IT Security > Hackers Exploit Vulnerability In The Elementor Pro WordPress Plugin
IT Security

Hackers Exploit Vulnerability In The Elementor Pro WordPress Plugin

The Elementor Pro WordPress plugin security flaw, described as a case of broken access control, impacting versions 3.11.6 and earlier is open to over 11 million websites globally

Editorial Desk
Last updated: April 2, 2023 5:21 pm
Editorial Desk
Share
SHARE

A high-severity vulnerability discovered by NinTechNet researcher Jerome Bruandet on March 18, 2023 in the widely used Elementor Pro WordPress plugin due to a flawed access control in the WooCommerce module utilised by over eleven million websites, is currently being exploited by hackers

Elementor Pro is a WordPress page builder plugin that facilitates the effortless creation of professional-looking websites, even for individuals who lack coding expertise.

The popular website builder plugin includes drag-and-drop functionality, theme building, a collection of templates, custom widget support, and a WooCommerce builder for online shops.

A vulnerability in version 3.11.6 and all preceding versions of the plugin enables authorised users, such as site members or shop customers, to modify site settings and execute a complete takeover of the site.

The researcher stated that the vulnerability is related to a flawed access control on the WooCommerce module (“elementor-pro/modules/woocommerce/module.php”) of the plugin. This flaw allows anyone to alter WordPress options in the database without undergoing proper validation.

The exploit of the vulnerability takes place through an insecure AJAX action called “pro_woocommerce_update_page_option.” This action suffers from inadequate input validation and a deficiency of capability checks.

In a technical writeup about the bug Bruandet says an authenticated attacker can leverage the vulnerability to create an administrator account by enabling registration and setting the default role to “administrator,” change the administrator email address or, redirect all traffic to an external malicious website by changing siteurl among many other possibilities.

It’s crucial to highlight that the exploitation of this specific vulnerability necessitates the installation of the WooCommerce plugin on the site, which triggers the corresponding vulnerable module on Elementor Pro.

PatchStack reports Elementor Plugin bug actively exploited

According to WordPress security firm PatchStack, hackers are currently exploiting the Elementor Pro plugin vulnerability by redirecting site visitors to malicious domains (“away[.]trackersline[.]com”) or uploading backdoors to the breached site.

The backdoors that are uploaded in these attacks have been named wp-resortpark.zip, wp-rate.php, or lll.zip.

This archive contains a PHP script that enables a remote attacker to upload additional files to the compromised server, thus providing them with complete access to the WordPress site. This access can be used to steal data or install further malicious code.

The exploitation of this vulnerability can also have catastrophic consequences for websites that utiliae the plugin, including the redirection of site visitors to malicious domains or the uploading of backdoors to the compromised website.

PatchStack has identified three IP addresses that most of the attacks targeting vulnerable websites originate from. Therefore, it is recommended to add these IP addresses to a blocklist.

  • 193.169.194.63
  • 193.169.195.64
  • 194.135.30.6

If your WordPress website uses Elementor Pro, it is critical to update to version 3.11.7 or newer without delay, as hackers are actively targeting sites that are vulnerable.

In light of these developments, it is imperative that websites using the Elementor Pro WordPress plugin update to version 3.11.7 (the most current version is 3.12.0) as soon as possible. Failure to do so could leave them vulnerable to hackers who are actively targeting sites with this vulnerability.

As the threat of cyberattacks continues to rise, it is crucial for website owners to prioritize cybersecurity and ensure that all plugins and software are up-to-date with the latest security patches. Failure to do so could lead to a devastating data breach or loss of sensitive information.

This is not the first time that WordPress plugins have been targeted by hackers. Last week, WordPress had to perform a forced update of the WooCommerce Payments plugin, which is utilised by online stores

ByEditorial Desk
The TBN team is a well establish group of technology industry professionals with backgrounds in IT Systems, Business Communications and Journalism.
Previous Article WILL A VPN KEEP YOU SAFE ? Do VPN Connections Really Keep You Safe Online?
Next Article ChatGPT education Critical Thinking tech news ChatGPT May Lead To The Downfall Of Education And Critical Thinking
Hackers exploit bug in Elementor Pro WordPress plugin hack - Tech News

Tech Articles

Google AdSense Revenue 2026

Google AdSense Crisis 2026: Publishers Report 90% Revenue Crash As AI Overviews Devastate Earnings

Publishers are reporting 50–90% Google AdSense revenue crashes in early…

January 24, 2026

How the World’s Data Centres Are Quietly Burning the Planet

Data centres are burning the planet, with a growing environmental…

March 11, 2026
Gmail AI is reading your emails — here is how to stop it

Your Gmail Account May Be Feeding Google’s AI—Here’s What You Need to Know

Your Gmail account may be contributing to Google’s AI systems…

January 26, 2026

Recent News

IT Security

Group-IB Opens Latest Digital Crime Resistance Center in Thailand

6 Min Read
Snow Flak what we can learn
IT Security

What Can We Learn From the Snowflake Attack? (Data Breach)

10 Min Read
Cloudflare's Q1 DDoS report finds 20.5M attacks – 358% increase YoY.
IT Security

Cloudflare’s Autonomous Systems Mitigated 20.5 Million DDoS Attacks

4 Min Read
Backdoor ESET named Dolphin ScarCruft APT group
IT Security

North Korea-linked group launches Dolphin backdoor, steals files and communicates via Google Drive

4 Min Read
Tech News

Tech Business News

In 2026, technology news is shaping business outcomes faster than ever—driven by AI adoption, rising cyber risk, cloud modernisation, data regulation, and constant platform change.


Tech News keeps Australian organisations and industry professionals informed with timely reporting and practical coverage across AI, cybersecurity, cloud, enterprise IT, startups, science, people and business, plus major world and local news impacting the tech sector.


Tech Business News publishes news and analysis designed to be clear, relevant, and easy to act on. It supports the industry with technology news reports, whitepaper publishing services, and a range of media, advertising and publishing options 

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

April, 14, 2026

Contact

Tech Business News
Melbourne, Australia
Werribee 3030
Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.

Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2026

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?