Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » Elementor CSRF Admin Account Vulnerability Earns CVSS 8.8 Score
    Technology

    Elementor CSRF Admin Account Vulnerability Earns CVSS 8.8 Score

    Gary BehanBy Gary Behan07/10/2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Elementor CSRF admin account vulnerability
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    A cross-site request forgery (CSRF) flaw in the Elementor WordPress plugin, now tracked as CVE-2026-62062, can allow an unauthenticated attacker to create administrator accounts on affected sites, and doing so requires nothing more than a single malicious link opened by a logged-in admin. The Elementor CSRF admin account vulnerability has been assigned a CVSS score of 8.8, according to Beacon Lab, placing it firmly in the high-severity bracket.

    How the Elementor CSRF Admin Account Vulnerability Works

    The flaw lives in Elementor’s Editor Events module. When processing requests, that module checks the raw request URI for the string elementor/v1/events/ and, if it finds it, skips WordPress’s REST nonce validation entirely. The problem, as Beacon Lab details, is that the bypass is triggered by the presence of the string in the URL, not by the requested endpoint actually belonging to the elementor/v1/events/ path. An attacker can simply append that string to a request targeting any other REST endpoint, and WordPress’s nonce check is silently bypassed.

    Because the URI also includes attacker-controlled query parameters, the crafted link can instruct the victim’s authenticated session to execute whichever REST API action their account is permitted to perform. On a default WordPress installation, a logged-in administrator’s permissions are broad enough that the practical outcome is the creation of a new admin account under the attacker’s control.

    Patchstack puts it plainly: ‘One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform.’ The attack needs no JavaScript, no attacker-controlled webpage and no submitted form. A link delivered by email, a chat message or even a comment on the target site is sufficient.

    Scope: Up to Two Million Sites on Vulnerable Versions

    The Elementor Website Builder is active on 10 million websites, making it one of the more widely deployed plugins in the WordPress ecosystem. The CSRF flaw, however, is confined to versions 4.3.0 and 4.3.1, which introduced the affected Editor Events proxy. According to statistics from WordPress.org, those two versions are in use on up to 2 million sites. Releases before 4.3.0 do not contain the vulnerable module, though older versions carry their own unrelated flaws, some of which are already being actively exploited.

    Patchstack received the vulnerability report from bug hunter ‘Saggre’ and passed it to the Elementor team on 22 September. The patch arrived quickly: Elementor released version 4.3.2 on 24 September 2026, according to Beacon Lab. The fix prevents attackers from triggering the nonce bypass through the query string.

    What Site Owners Should Do Now

    The remediation advice is straightforward: upgrade to Elementor version 4.3.2 as soon as possible. Sites still running 4.3.0 or 4.3.1 remain exposed to a one-click attack that can hand a complete stranger the keys to a WordPress installation. Given that the attack vector requires no special tooling and can be delivered through everyday communication channels, the window for complacency is short.

    The CVE identifier for the Elementor CSRF admin account vulnerability (CVE-2026-62062) had not yet been assigned at the time Patchstack initially reported it, and the flaw was patched before a public identifier appeared. That timeline is now filled in, with Beacon Lab’s advisory confirming both the CVE number and the 8.8 CVSS score. Sites that have already updated to 4.3.2 are protected; the roughly two million still on the affected versions have a concrete, tested fix waiting for them in the plugin dashboard.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleAnthropic Offers Free Credits for Claude Code Cloud Sessions, With a Catch
    Next Article Kiteworks Zero-Day Server Shutdown Advised After Law Enforcement Alert
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    Bitget Bitcoin withdrawals resume after $387.5m North Korean hack

    09/10/2026

    Cameron Wagenius Hacking Sentence: 70 Months for Extorting Ten Telecoms

    09/10/2026

    OpenAI Always-On Assistant ‘o’ Spotted in ChatGPT Pro Ahead of DevDay

    09/10/2026

    Citrix NetScaler Zero-Day RCE Flaws Patched After Active Exploitation Confirmed Worldwide

    08/10/2026

    ShinyHunters WAF bypass PeopleSoft attacks spread to dozens of new systems

    08/10/2026

    Claude Opus 5.5 Writing Style Shifts: 95% Fewer Em Dashes, Shorter Sentences

    08/10/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.