Skip to content

✅ 🐞 Mixpanel events proxy sends its own Authorization header and breaks HTTP Basic Auth protected sites #37421

Description

@mokabiwd

Description

Since Elementor 4.3.0, sites protected by HTTP Basic Auth (typical staging / preproduction setup) keep showing the browser's Basic Auth prompt in wp-admin. This is a regression: it does not happen with Elementor 4.2.4. Observed in Chrome 153 (several profiles). Firefox is not affected.

Root cause

  • 4.3.0 introduced a same-origin proxy for Mixpanel (core/common/modules/events-manager/rest-api/events-proxy-rest-api.php). In assets/js/common.js, Mixpanel is now initialized with api_host: elementorCommon.config.editor_events.proxy_api_host (= /wp-json/elementor/v1/events/api). In 4.2.4 it was https://api-eu.mixpanel.com.
  • The Mixpanel JS library ($lib_version=2.71.1, flags: true) authenticates its flags requests with its own header: Authorization: Basic base64("<ELEMENTOR_EDITOR_EVENTS_MIXPANEL_TOKEN>:").
  • Example request from wp-admin:
    GET /wp-json/elementor/v1/events/api/flags/?context=…&token=150605b3b9f979922f2ac5a52e2dcfe9&mp_lib=web&$lib_version=2.71.1
    with Authorization: Basic MTUwNjA1YjNiOWY5Nzk5MjJmMmFjNWE1MmUyZGNmZTk6 (decodes to 150605b3b9f979922f2ac5a52e2dcfe9:).
  • In 4.2.x this header went to mixpanel.com (another origin), so it was harmless. It now goes to the site itself. It replaces the user's Basic Auth credentials, the web server returns 401, and Chrome drops its cached credentials for the realm. All following same-origin requests (REST API, admin-ajax, images, favicon) are then sent without Authorization, get a 401, and the prompt appears again.

Workaround

Define the token as empty before Elementor loads (wp-config.php):

define( 'ELEMENTOR_EDITOR_EVENTS_MIXPANEL_TOKEN', '' );

Module::can_send_events() then returns false and no proxy requests are sent. Disabling "Usage Data Sharing" also works.

Suggested fix

Do not send a client-side Authorization header to the same-origin proxy. For example, keep the token in the query string only (it is already there) or add Mixpanel authentication on the server side in the proxy.

Steps to reproduce

  1. Clean WordPress 7.1.2 install with Elementor 4.3.0 active.
  2. Protect the whole site with HTTP Basic Auth, for example:
    • Apache (.htaccess):
      AuthType Basic
      AuthName "Restricted"
      AuthUserFile /path/to/.htpasswd
      Require valid-user
    • or nginx (server block):
      auth_basic "Restricted";
      auth_basic_user_file /path/to/.htpasswd;
  3. In Elementor → Settings, enable "Usage Data Sharing" (or accept it in the onboarding notice), and make sure the "Editor Events" experiment is active (default).
  4. Open /wp-admin/ in Google Chrome, enter the Basic Auth credentials, then log in to WordPress.
  5. Open DevTools → Network, enable "Preserve log", and browse a few admin pages (Dashboard, Pages, Elementor editor).
  6. Filter on events/api/flags: the request /wp-json/elementor/v1/events/api/flags/?…&token=… is sent with Authorization: Basic <base64 of "<mixpanel token>:"> instead of the user's credentials, and the server answers 401.
  7. Right after that, the Basic Auth prompt shows again. Following same-origin requests (REST API, admin-ajax, images, favicon) are sent without any Authorization header and also get a 401.
  8. Downgrade to Elementor 4.2.4 and repeat: flags requests go to api-eu.mixpanel.com and the prompt never shows up again.

Expected behavior

Elementor's telemetry should never override the site's HTTP authentication. Requests to the same-origin events proxy should not carry an Authorization header, so that the browser keeps sending the user's cached Basic Auth credentials and wp-admin works without repeated prompts, as with Elementor 4.2.4.

Elementor System Info

Click to reveal
== Server Environment ==
	Operating System: Linux
	Software: nginx/1.28.0
	MySQL version: MariaDB 10.5.28
	PHP Version: 8.5.10
	PHP Memory Limit: 512M
	PHP Max Input Vars: 1000
	PHP Max Post Size: 128M
	GD Installed: Yes
	ZIP Installed: Yes
	Write Permissions: All right
	Elementor Library: Connected

== WordPress Environment ==
	Version: 7.1.2
	Site URL: https://staging.example.com/wp
	Home URL: https://staging.example.com
	WP Multisite: No
	Permalink Structure: /%postname%/
	Language: fr_FR
	Debug Mode: Inactive
	Note: Bedrock layout, whole site protected by HTTP Basic Auth

== Theme ==
	Custom child theme of OceanWP 4.2.6

== User ==
	Role: administrator
	User Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36

== Active Plugins ==
	Elementor 4.3.0
	Elementor Pro 4.3.0
	Autoptimize 3.1.15.1
	Axeptio 2.6.5
	Converter for Media 6.6.5
	Disable Comments 2.9.0
	Disable WP REST API 2.6.9
	Enable Media Replace 4.2.2
	Gravity Forms 3.1.2 (+ Multilingual 1.8.5, reCAPTCHA 2.2.2)
	Ocean Extra 2.6.2, Ocean Sticky Header 2.2.5
	Redirection 5.10.1
	View Transitions 1.2.1
	Wordfence Security 9.0.1
	WP Consent API 2.1.0
	WP Mail Logging 1.17.0, WP Mail SMTP 4.9.0
	WPML Multilingual CMS 4.9.7 (+ Media Translation 3.1.2, SEO 2.2.5, String Translation 3.5.4)
	WPS Hide Login 1.9.19
	WP Store Locator 3.0.0 (+ CSV Manager 2.2.0, Statistics 2.0.1, Widget 2.1.0)
	Yoast SEO 28.5
	+ 5 private custom plugins (not involved: the issue is in Elementor's events proxy)

== Must-Use Plugins ==
	Bedrock Autoloader

== Elements Usage ==
	Redacted (not relevant)

== Settings ==
	allow_tracking: yes
	font_display: swap

== Features ==
	Custom Fonts: 0
	Custom Icons: 0

== Integrations ==

== Elementor Experiments ==
	Editor Events (Évènements de l'éditeur Elementor): Active by default
	Editor V4: Active by default
	Atomic Widgets: Active by default
	Atomic Form: Active by default
	Container: Active by default
	Nested Elements: Active by default
	(others: defaults)

== Log ==
	2026-09-23 10:07:23 [info] Update DB has been started [Elementor, from 4.2.4 to 4.3.0]
	(the issue started right after this update; other log entries are unrelated)

== Elementor - Compatibility Tag ==
	Elementor Pro: Compatibility not specified

== Elementor Pro - Compatibility Tag ==

Agreement

  • I confirm I have read and followed all the guidelines and instructions outlined in the Elementor Bug Report form.
  • I agree that my issue may be closed without further action if it doesn't meet all the requirements outlined in the Elementor Bug Report form.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugIndicates a bug with one or multiple components.component/codeIndicates when a topic is related to a component’s code.component/connectReferences any component related to the Elementor Connect - License Activation, Library Connection,component/rest-apiReferences any instance, integration, or implementation of the REST-API.mod*[Temp.] For internal use only.mod/b*[Temp.] For internal use only.mod/c*[Temp.] For internal use only.mod/s*[Temp.] For internal use only.solvedIndicates that an Issue has been Solved, or a Feature Request has been Released.status/mergedIndicates when a Pull Request has been merged to a Release.

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions