Intel

AIKIDO-2026-899801

Elementor is vulnerable to Cross-Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF)CVE-2026-62062 Published Yesterday

88

High Risk

This Affects:

PHPElementor
4.3.0 - 4.3.1
Fixed in 4.3.2
Are you affected? Scan for Free

TL;DR

Events_Proxy_REST_API::bypass_nonce_check_for_own_routes treats any request URI containing elementor/v1/events/ as one of its own routes and returns authentication success before WordPress verifies the REST nonce. is_own_route_request searches the raw URI, which includes attacker-controlled query parameters, so an unauthenticated attacker can append that marker to an unrelated REST request and induce a logged-in user to execute it with their existing permissions. If an administrator opens a crafted link, the attacker can create a new administrator account and take over the site. The fix checks the resolved REST route instead of the raw URI and requires the Elementor events namespace at the start of the route.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and a logged-in WordPress user can be induced to open an attacker-crafted link.

Background info

Elementor is vulnerable to Cross-Site Request Forgery (CSRF) in versions 4.3.0 - 4.3.1.

How to fix this

Upgrade the Elementor library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform