Elementor WordPress flaw lets attackers create admin accounts
2026-09-25T19:23:21Z•201364b85373b702faa01a72d362c54675481021545855f26f53946820ee518d
CVE-2026-5430CISACSRFCarbonatoDockerElementorGitLabMacSyncNorth-Korea-linked-activityRoundcubeWSO2WordPressaccount-takeoveractive-exploitationcloud-abusecode-injectioncryptocurrency-theftcybercrimemacOS-malwarevulnerability
What happened
BleepingComputer security feed containing reports on actively exploited vulnerabilities, malware campaigns, cybercrime, and security-relevant technology developments. Key threats include a WordPress Elementor CSRF flaw enabling unauthenticated administrator account creation, exploitation of WSO2 authentication bypass CVE-2026-5430, active exploitation of a Roundcube code-injection vulnerability, Carbonato malware targeting exposed Docker daemons, MacSync malware using public iCloud calendars for payload delivery, and a major Bitget cryptocurrency theft attributed to suspected North Korean604?
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 201364b85373b702faa01a72d362c54675481021545855f26f53946820ee518d
- Enrichment time
- 2026-09-25T19:23:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.