PT-2026-98356 · WordPress · Elementor Pro+1

CVE-2026-62062

·

Published

2026-09-25

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elementor Website Builder versions 4.3.0 through 4.3.1 Elementor Pro versions 4.3.0 through 4.3.1
Description A Cross-Site Request Forgery (CSRF) flaw exists where a logged-in administrator can be tricked into opening a crafted link, leading to the creation of a new administrator account. This issue occurs because the software disables the WordPress REST API nonce check for all REST routes, not only those specific to Elementor. A nonce is a unique token used to verify that a request was intentionally sent by the user.
Recommendations Update Elementor Website Builder to version 4.3.2. Update Elementor Pro to version 4.3.2.

Fix

RCE

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62062

Affected Products

Elementor Pro
Elementor Website Builder