Elementor patches a CSRF flaw that can create a rogue admin
A crafted link is enough to trick a logged-in administrator into an unintended action. Update to 4.3.2 if you run the page builder on 10 million sites.
Elementor, the WordPress page builder installed on more than 10 million sites, has patched a cross-site request forgery vulnerability tracked as CVE-2026-62062.
The flaw, rated 8.8 on the CVSS scale, affects versions 4.3.0 and 4.3.1. Patchstack, credited to researcher Saggre, classes it under OWASP’s broken-access-control category: a logged-in user, most usefully an administrator, can be tricked into performing an action they didn’t intend simply by visiting a crafted link. Elementor shipped the fix in 4.3.2 on 24 September; the public changelog only says “improved code security enforcement in data handling,” which is typical for a plugin that doesn’t want to draw a map to the bug for anyone still on the old version.
Why it matters: CSRF on an admin session is a route to full site compromise, and it doesn’t need a leaked password or a login form to exploit, just an admin clicking a link in an email, a comment, or a support ticket. If you or a client runs Elementor, check the version number now rather than waiting for auto-update to catch up.
The caveat: exploitation still requires a logged-in administrator to interact with a malicious link, so it’s not a wormable, no-touch bug. That makes it serious rather than critical, but it’s still worth acting on this week, not next.