Description
Since Elementor 4.3.0, sites protected by HTTP Basic Auth (typical staging / preproduction setup) keep showing the browser's Basic Auth prompt in wp-admin. This is a regression: it does not happen with Elementor 4.2.4. Observed in Chrome 153 (several profiles). Firefox is not affected.
Root cause
- 4.3.0 introduced a same-origin proxy for Mixpanel (
core/common/modules/events-manager/rest-api/events-proxy-rest-api.php). In assets/js/common.js, Mixpanel is now initialized with api_host: elementorCommon.config.editor_events.proxy_api_host (= /wp-json/elementor/v1/events/api). In 4.2.4 it was https://api-eu.mixpanel.com.
- The Mixpanel JS library (
$lib_version=2.71.1, flags: true) authenticates its flags requests with its own header: Authorization: Basic base64("<ELEMENTOR_EDITOR_EVENTS_MIXPANEL_TOKEN>:").
- Example request from wp-admin:
GET /wp-json/elementor/v1/events/api/flags/?context=…&token=150605b3b9f979922f2ac5a52e2dcfe9&mp_lib=web&$lib_version=2.71.1
with Authorization: Basic MTUwNjA1YjNiOWY5Nzk5MjJmMmFjNWE1MmUyZGNmZTk6 (decodes to 150605b3b9f979922f2ac5a52e2dcfe9:).
- In 4.2.x this header went to mixpanel.com (another origin), so it was harmless. It now goes to the site itself. It replaces the user's Basic Auth credentials, the web server returns 401, and Chrome drops its cached credentials for the realm. All following same-origin requests (REST API, admin-ajax, images, favicon) are then sent without
Authorization, get a 401, and the prompt appears again.
Workaround
Define the token as empty before Elementor loads (wp-config.php):
define( 'ELEMENTOR_EDITOR_EVENTS_MIXPANEL_TOKEN', '' );
Module::can_send_events() then returns false and no proxy requests are sent. Disabling "Usage Data Sharing" also works.
Suggested fix
Do not send a client-side Authorization header to the same-origin proxy. For example, keep the token in the query string only (it is already there) or add Mixpanel authentication on the server side in the proxy.
Steps to reproduce
- Clean WordPress 7.1.2 install with Elementor 4.3.0 active.
- Protect the whole site with HTTP Basic Auth, for example:
- Apache (
.htaccess):
AuthType Basic
AuthName "Restricted"
AuthUserFile /path/to/.htpasswd
Require valid-user
- or nginx (server block):
auth_basic "Restricted";
auth_basic_user_file /path/to/.htpasswd;
- In Elementor → Settings, enable "Usage Data Sharing" (or accept it in the onboarding notice), and make sure the "Editor Events" experiment is active (default).
- Open
/wp-admin/ in Google Chrome, enter the Basic Auth credentials, then log in to WordPress.
- Open DevTools → Network, enable "Preserve log", and browse a few admin pages (Dashboard, Pages, Elementor editor).
- Filter on
events/api/flags: the request /wp-json/elementor/v1/events/api/flags/?…&token=… is sent with Authorization: Basic <base64 of "<mixpanel token>:"> instead of the user's credentials, and the server answers 401.
- Right after that, the Basic Auth prompt shows again. Following same-origin requests (REST API, admin-ajax, images, favicon) are sent without any
Authorization header and also get a 401.
- Downgrade to Elementor 4.2.4 and repeat: flags requests go to
api-eu.mixpanel.com and the prompt never shows up again.
Expected behavior
Elementor's telemetry should never override the site's HTTP authentication. Requests to the same-origin events proxy should not carry an Authorization header, so that the browser keeps sending the user's cached Basic Auth credentials and wp-admin works without repeated prompts, as with Elementor 4.2.4.
Elementor System Info
Click to reveal
== Server Environment ==
Operating System: Linux
Software: nginx/1.28.0
MySQL version: MariaDB 10.5.28
PHP Version: 8.5.10
PHP Memory Limit: 512M
PHP Max Input Vars: 1000
PHP Max Post Size: 128M
GD Installed: Yes
ZIP Installed: Yes
Write Permissions: All right
Elementor Library: Connected
== WordPress Environment ==
Version: 7.1.2
Site URL: https://staging.example.com/wp
Home URL: https://staging.example.com
WP Multisite: No
Permalink Structure: /%postname%/
Language: fr_FR
Debug Mode: Inactive
Note: Bedrock layout, whole site protected by HTTP Basic Auth
== Theme ==
Custom child theme of OceanWP 4.2.6
== User ==
Role: administrator
User Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36
== Active Plugins ==
Elementor 4.3.0
Elementor Pro 4.3.0
Autoptimize 3.1.15.1
Axeptio 2.6.5
Converter for Media 6.6.5
Disable Comments 2.9.0
Disable WP REST API 2.6.9
Enable Media Replace 4.2.2
Gravity Forms 3.1.2 (+ Multilingual 1.8.5, reCAPTCHA 2.2.2)
Ocean Extra 2.6.2, Ocean Sticky Header 2.2.5
Redirection 5.10.1
View Transitions 1.2.1
Wordfence Security 9.0.1
WP Consent API 2.1.0
WP Mail Logging 1.17.0, WP Mail SMTP 4.9.0
WPML Multilingual CMS 4.9.7 (+ Media Translation 3.1.2, SEO 2.2.5, String Translation 3.5.4)
WPS Hide Login 1.9.19
WP Store Locator 3.0.0 (+ CSV Manager 2.2.0, Statistics 2.0.1, Widget 2.1.0)
Yoast SEO 28.5
+ 5 private custom plugins (not involved: the issue is in Elementor's events proxy)
== Must-Use Plugins ==
Bedrock Autoloader
== Elements Usage ==
Redacted (not relevant)
== Settings ==
allow_tracking: yes
font_display: swap
== Features ==
Custom Fonts: 0
Custom Icons: 0
== Integrations ==
== Elementor Experiments ==
Editor Events (Évènements de l'éditeur Elementor): Active by default
Editor V4: Active by default
Atomic Widgets: Active by default
Atomic Form: Active by default
Container: Active by default
Nested Elements: Active by default
(others: defaults)
== Log ==
2026-09-23 10:07:23 [info] Update DB has been started [Elementor, from 4.2.4 to 4.3.0]
(the issue started right after this update; other log entries are unrelated)
== Elementor - Compatibility Tag ==
Elementor Pro: Compatibility not specified
== Elementor Pro - Compatibility Tag ==
Agreement
Description
Since Elementor 4.3.0, sites protected by HTTP Basic Auth (typical staging / preproduction setup) keep showing the browser's Basic Auth prompt in wp-admin. This is a regression: it does not happen with Elementor 4.2.4. Observed in Chrome 153 (several profiles). Firefox is not affected.
Root cause
core/common/modules/events-manager/rest-api/events-proxy-rest-api.php). Inassets/js/common.js, Mixpanel is now initialized withapi_host: elementorCommon.config.editor_events.proxy_api_host(=/wp-json/elementor/v1/events/api). In 4.2.4 it washttps://api-eu.mixpanel.com.$lib_version=2.71.1,flags: true) authenticates its flags requests with its own header:Authorization: Basic base64("<ELEMENTOR_EDITOR_EVENTS_MIXPANEL_TOKEN>:").GET /wp-json/elementor/v1/events/api/flags/?context=…&token=150605b3b9f979922f2ac5a52e2dcfe9&mp_lib=web&$lib_version=2.71.1with
Authorization: Basic MTUwNjA1YjNiOWY5Nzk5MjJmMmFjNWE1MmUyZGNmZTk6(decodes to150605b3b9f979922f2ac5a52e2dcfe9:).Authorization, get a 401, and the prompt appears again.Workaround
Define the token as empty before Elementor loads (wp-config.php):
Module::can_send_events()then returns false and no proxy requests are sent. Disabling "Usage Data Sharing" also works.Suggested fix
Do not send a client-side
Authorizationheader to the same-origin proxy. For example, keep the token in the query string only (it is already there) or add Mixpanel authentication on the server side in the proxy.Steps to reproduce
.htaccess):AuthType Basic
AuthName "Restricted"
AuthUserFile /path/to/.htpasswd
Require valid-user
auth_basic "Restricted";
auth_basic_user_file /path/to/.htpasswd;
/wp-admin/in Google Chrome, enter the Basic Auth credentials, then log in to WordPress.events/api/flags: the request/wp-json/elementor/v1/events/api/flags/?…&token=…is sent withAuthorization: Basic <base64 of "<mixpanel token>:">instead of the user's credentials, and the server answers 401.Authorizationheader and also get a 401.api-eu.mixpanel.comand the prompt never shows up again.Expected behavior
Elementor's telemetry should never override the site's HTTP authentication. Requests to the same-origin events proxy should not carry an
Authorizationheader, so that the browser keeps sending the user's cached Basic Auth credentials and wp-admin works without repeated prompts, as with Elementor 4.2.4.Elementor System Info
Click to reveal
Agreement