ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
A CSRF flaw in Elementor versions 4.3.0 and 4.3.1 lets unauthenticated attackers trick logged-in administrators into creating rogue admin accounts via a malicious link. Patchstack reported it September 22; Elementor fixed it in 4.3.2 two days later. The plugin runs on 10 million sites, with up to 2 million on vulnerable versions.
Tap to vote and see what everyone thinks.
Summary by ByteBrief