Elementor Website Builder CVE-2026-62062 (CVSS 8.8): CSRF via elementor/v1/events/ URI check → admin account creation — fix 4.3.2
Patchstack (public 25 September 2026; reported by Saggre 22 Sep; fixed 24 Sep) documents CVE-2026-62062 in Elementor Website Builder 4.3.0 and 4.3.1 only: the Editor Events module disabled WordPress REST CSRF/nonce protection whenever the literal string elementor/v1/events/ appeared anywhere in the raw request URI (including attacker-controlled query string). A one-click link opened by a logged-in administrator can force any REST action that account may perform — on a stock install, creation of an attacker-controlled administrator. No JavaScript or attacker-hosted form required. Patchstack CVSS 3.1 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H); ~2M sites on the two affected versions per WordPress.org stats cited by Patchstack/BleepingComputer. Fix 4.3.2 checks resolved rest_route instead of raw URI. Distinct from Elementor Pro form-upload CVE-2026-32475 (desk card). Primary: Patchstack advisory + database; wire: BleepingComputer 25 Sep 2026.
- Product
- Elementor Website Builder (WordPress plugin; free)
- Versions
- Affected: 4.3.0 and 4.3.1 only. Fixed: 4.3.2+. Pre-4.3.0 lacks this Editor Events proxy (other Elementor flaws may still apply).
- CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Exploited in Australia?
- unknown
- Patch to
- Update Elementor to 4.3.2 or later immediately; audit wp_users for unexpected administrators created since 22 Sep; remind admins not to open unsolicited “verify / preview” links while logged into wp-admin
Primary: Patchstack — Elementor CSRF affecting 2M+ sites / CVE-2026-62062 (25 Sep 2026) · Vendor: Patchstack database — CVE-2026-62062 (Elementor 4.3.0–4.3.1 → 4.3.2) · CVE: CVE-2026-62062, CVE-2026-32475 · BleepingComputer — Elementor CSRF → admin account (25 Sep 2026)
