PT-2026-98356 · WordPress · Elementor Pro+1
CVE-2026-62062
·
Published
2026-09-25
·
Updated
2026-09-28
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Elementor Website Builder versions 4.3.0 through 4.3.1
Elementor Pro versions 4.3.0 through 4.3.1
Description
A Cross-Site Request Forgery (CSRF) flaw exists where a logged-in administrator can be tricked into opening a crafted link, leading to the creation of a new administrator account. This issue occurs because the software disables the WordPress REST API nonce check for all REST routes, not only those specific to Elementor. A nonce is a unique token used to verify that a request was intentionally sent by the user.
Recommendations
Update Elementor Website Builder to version 4.3.2.
Update Elementor Pro to version 4.3.2.
Fix
RCE
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elementor Pro
Elementor Website Builder