Vulnerability in Elementor Website Builder – more than just a page builder — CVE-2026-62062
What to do now
Update Elementor Website Builder – more than just a page builder to 4.3.2 or later.
Affected versions
- 4.3.0 to 4.3.1 (inclusive)
Affected: Elementor Website Builder – more than just a page builder (plugin, elementor)
What the vulnerability is
The Elementor Website Builder – more than just a page builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.3.0 to 4.3.1. This is due to missing or incorrect nonce validation on the is_own_route_request function. This makes it possible for unauthenticated attackers to perform any authenticated REST action available to the victim's role, including creating administrator-level accounts, modifying site options, or deleting content, while the victim's cookie session remains fully authenticated via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.