CVE-2026-62062: WordPress Elementor Website Builder plugin <= 4.3.1 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery.
This issue affects Elementor Website Builder: from n/a through 4.3.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Elementor Website Builder pluginto a version that resolves this vulnerability.Fixed in 4.3.2
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack vector is network-based and requires user interaction. No attacker privileges are required, so exploitation would depend on convincing a user to perform an action through a crafted request.
Which versions should be treated as affected?
Elementor Website Builder versions through 4.3.1 are affected. The available data does not identify a fixed version.
What is the potential impact if exploitation succeeds?
The vulnerability is rated high with a CVSS score of 8.8 and indicates high impact to confidentiality, integrity, and availability. The scope is unchanged.