A cross-site request forgery (CSRF) flaw in the Elementor WordPress plugin, now tracked as CVE-2026-62062, can allow an unauthenticated attacker to create administrator accounts on affected sites, and doing so requires nothing more than a single malicious link opened by a logged-in admin. The Elementor CSRF admin account vulnerability has been assigned a CVSS score of 8.8, according to Beacon Lab, placing it firmly in the high-severity bracket.
How the Elementor CSRF Admin Account Vulnerability Works
The flaw lives in Elementor’s Editor Events module. When processing requests, that module checks the raw request URI for the string elementor/v1/events/ and, if it finds it, skips WordPress’s REST nonce validation entirely. The problem, as Beacon Lab details, is that the bypass is triggered by the presence of the string in the URL, not by the requested endpoint actually belonging to the elementor/v1/events/ path. An attacker can simply append that string to a request targeting any other REST endpoint, and WordPress’s nonce check is silently bypassed.
Because the URI also includes attacker-controlled query parameters, the crafted link can instruct the victim’s authenticated session to execute whichever REST API action their account is permitted to perform. On a default WordPress installation, a logged-in administrator’s permissions are broad enough that the practical outcome is the creation of a new admin account under the attacker’s control.
Patchstack puts it plainly: ‘One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform.’ The attack needs no JavaScript, no attacker-controlled webpage and no submitted form. A link delivered by email, a chat message or even a comment on the target site is sufficient.
Scope: Up to Two Million Sites on Vulnerable Versions
The Elementor Website Builder is active on 10 million websites, making it one of the more widely deployed plugins in the WordPress ecosystem. The CSRF flaw, however, is confined to versions 4.3.0 and 4.3.1, which introduced the affected Editor Events proxy. According to statistics from WordPress.org, those two versions are in use on up to 2 million sites. Releases before 4.3.0 do not contain the vulnerable module, though older versions carry their own unrelated flaws, some of which are already being actively exploited.
Patchstack received the vulnerability report from bug hunter ‘Saggre’ and passed it to the Elementor team on 22 September. The patch arrived quickly: Elementor released version 4.3.2 on 24 September 2026, according to Beacon Lab. The fix prevents attackers from triggering the nonce bypass through the query string.
What Site Owners Should Do Now
The remediation advice is straightforward: upgrade to Elementor version 4.3.2 as soon as possible. Sites still running 4.3.0 or 4.3.1 remain exposed to a one-click attack that can hand a complete stranger the keys to a WordPress installation. Given that the attack vector requires no special tooling and can be delivered through everyday communication channels, the window for complacency is short.
The CVE identifier for the Elementor CSRF admin account vulnerability (CVE-2026-62062) had not yet been assigned at the time Patchstack initially reported it, and the flaw was patched before a public identifier appeared. That timeline is now filled in, with Beacon Lab’s advisory confirming both the CVE number and the 8.8 CVSS score. Sites that have already updated to 4.3.2 are protected; the roughly two million still on the affected versions have a concrete, tested fix waiting for them in the plugin dashboard.

