Elementor 4.3.0 and 4.3.1 contain a CSRF flaw that can create an admin account when a logged-in administrator opens a crafted ...