Alert

Alert 2026-109 CSRF Vulnerability in Elementor Website Builder for WordPress

Affected product(s):

ProductAffected versionsFixed version
Elementor Website Builder for WordPress4.3.0 and 4.3.14.3.2 or later
Elementor ProNot directly part of this advisoryValidate and apply their security updates separately

Description

A Cross-Site Request Forgery (CSRF) vulnerability was published in the Elementor Website Builder plugin for WordPress, labeled as CVE‑2026‑62062 with a CVSS score of 8.8. The flaw exclusively affects versions 4.3.0 and 4.3.1 and was fixed in version 4.3.2, released on September 24, 2026.

CVE‑2026‑62062 is a CSRF vulnerability, classified as CWE‑352, caused by a bypass of the WordPress REST nonce validation in Elementor’s Editor Events module.

The REST nonce is the WordPress control designed to prevent CSRF attacks on cookie-authenticated requests. The Elementor flaw allowed any REST API endpoint to be excluded from that validation by adding the indicated text to the URL, without the requested endpoint actually belonging to elementor/v1/events/.

In versions 4.3.0 and 4.3.1, Elementor disables WordPress’s CSRF protection for cookie-authenticated requests if it detects the literal string elementor/v1/events/ anywhere in the request URI. Since WordPress includes the query string (query string) in that URI and the attacker can control the parameters of a link, an attacker can add that string to a different REST API request to cause Elementor to skip the nonce validation.

Additional information: