CVE-2026-62062
8.8Elementor · Elementor Website Builder
A Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows unauthenticated attackers to perform unauthorized actions on behalf of a victim.
Executive summary
Elementor Website Builder is vulnerable to a Cross-Site Request Forgery (CSRF) flaw, which could allow an attacker to perform unauthorized, high-impact actions on an affected WordPress site.
Vulnerability
The plugin fails to properly validate requests, allowing an unauthenticated attacker to trick a logged-in administrator or user into executing unintended actions via a crafted request. This Cross-Site Request Forgery (CWE-352) flaw impacts the integrity and availability of the affected WordPress installation.
Business impact
Successful exploitation allows an attacker to perform actions with the privileges of the victim, such as modifying site content, injecting malicious scripts, or changing site settings. Given the CVSS score of 8.8, this vulnerability represents a high risk to business operations, as it could lead to complete site compromise or unauthorized administrative changes without the user's consent.
Remediation
Immediate Action: Update the Elementor Website Builder plugin to version 4.3.2 or later immediately to apply the vendor-supplied security fix.
Proactive Monitoring: Review WordPress administrative access logs for suspicious activity or unauthorized configuration changes that occur during peak traffic hours.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block suspicious cross-site requests targeting WordPress plugins.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Due to the high severity of this vulnerability and the potential for full administrative takeover of the WordPress site, immediate patching is required. Administrators should verify their current version of Elementor and upgrade to 4.3.2 or higher as a priority to eliminate this risk.
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Saggre | Patchstack Bug Bounty Program, per the CVE Program record.