CVE-2026-62062

8.8

Elementor · Elementor Website Builder

A Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows unauthenticated attackers to perform unauthorized actions on behalf of a victim.

Executive summary

Elementor Website Builder is vulnerable to a Cross-Site Request Forgery (CSRF) flaw, which could allow an attacker to perform unauthorized, high-impact actions on an affected WordPress site.

Vulnerability

The plugin fails to properly validate requests, allowing an unauthenticated attacker to trick a logged-in administrator or user into executing unintended actions via a crafted request. This Cross-Site Request Forgery (CWE-352) flaw impacts the integrity and availability of the affected WordPress installation.

Business impact

Successful exploitation allows an attacker to perform actions with the privileges of the victim, such as modifying site content, injecting malicious scripts, or changing site settings. Given the CVSS score of 8.8, this vulnerability represents a high risk to business operations, as it could lead to complete site compromise or unauthorized administrative changes without the user's consent.

Remediation

Immediate Action: Update the Elementor Website Builder plugin to version 4.3.2 or later immediately to apply the vendor-supplied security fix.

Proactive Monitoring: Review WordPress administrative access logs for suspicious activity or unauthorized configuration changes that occur during peak traffic hours.

Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block suspicious cross-site requests targeting WordPress plugins.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Due to the high severity of this vulnerability and the potential for full administrative takeover of the WordPress site, immediate patching is required. Administrators should verify their current version of Elementor and upgrade to 4.3.2 or higher as a priority to eliminate this risk.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Saggre | Patchstack Bug Bounty Program, per the CVE Program record.