WP Vulnerability WatchVulnerability data as of September 27, 2026

Vulnerability alerts / September 25, 2026

Vulnerability in Elementor Website Builder – more than just a page builder — CVE-2026-62062

HighSeverity
CVSS 8.8
0.1%Estimated exploit probability
EPSS
10,000,000+ sitesInstalls
4.3.2Fixed in

What to do now

Update Elementor Website Builder – more than just a page builder to 4.3.2 or later.

Affected versions

  • 4.3.0 to 4.3.1 (inclusive)

Affected: Elementor Website Builder – more than just a page builder (plugin, elementor)

Check: The plugin on wordpress.org / Our record for Elementor Website Builder – more than just a page builder

What the vulnerability is

The Elementor Website Builder – more than just a page builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.3.0 to 4.3.1. This is due to missing or incorrect nonce validation on the is_own_route_request function. This makes it possible for unauthenticated attackers to perform any authenticated REST action available to the victim's role, including creating administrator-level accounts, modifying site options, or deleting content, while the victim's cookie session remains fully authenticated via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/7bea239c-8af6-4492-baf7-e63de2750005
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts