Skip to content

Elementor patches a CSRF flaw that can create a rogue admin

A crafted link is enough to trick a logged-in administrator into an unintended action. Update to 4.3.2 if you run the page builder on 10 million sites.

Source: Patchstack

Elementor, the WordPress page builder installed on more than 10 million sites, has patched a cross-site request forgery vulnerability tracked as CVE-2026-62062.

The flaw, rated 8.8 on the CVSS scale, affects versions 4.3.0 and 4.3.1. Patchstack, credited to researcher Saggre, classes it under OWASP’s broken-access-control category: a logged-in user, most usefully an administrator, can be tricked into performing an action they didn’t intend simply by visiting a crafted link. Elementor shipped the fix in 4.3.2 on 24 September; the public changelog only says “improved code security enforcement in data handling,” which is typical for a plugin that doesn’t want to draw a map to the bug for anyone still on the old version.

Why it matters: CSRF on an admin session is a route to full site compromise, and it doesn’t need a leaked password or a login form to exploit, just an admin clicking a link in an email, a comment, or a support ticket. If you or a client runs Elementor, check the version number now rather than waiting for auto-update to catch up.

The caveat: exploitation still requires a logged-in administrator to interact with a malicious link, so it’s not a wormable, no-touch bug. That makes it serious rather than critical, but it’s still worth acting on this week, not next.

Share

Related reading

More from The Wire

All briefs