Description
Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery.

This issue affects Elementor Website Builder: from n/a through 4.3.1.
Published: 2026-09-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Request Forgery
Action: Apply Update
AI Analysis

Impact

This vulnerability is a Cross‑Site Request Forgery flaw in the Elementor Website Builder plugin for WordPress. It could allow an attacker to trick an authenticated user into submitting requests to the site, potentially enabling unauthorized changes.

Affected Systems

The affected product is the WordPress Elementor Website Builder plugin provided by Elementor. All releases from the initial version up through 4.3.1 contain the flaw. Site administrators should verify the installed version and apply an update if necessary.

Risk and Exploitability

The CVSS base score of 8.8 indicates high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Inferred that exploitation requires an authenticated user and could be performed via a malicious webpage or other forged request techniques. Given the high CVSS, the risk is significant for sites with administrative users.

Generated by OpenCVE AI on September 25, 2026 at 08:47 UTC.

Remediation

Vendor Solution

Update the WordPress Elementor Website Builder plugin to the latest available version (at least 4.3.2).


OpenCVE Recommended Actions

  • Update the WordPress Elementor Website Builder plugin to version 4.3.2 or newer.
  • If an update is not immediately possible, restrict access to the plugin’s administrative pages to prevent CSRF exploitation.
  • Review site logs for any unauthorized changes after applying the fix.

Generated by OpenCVE AI on September 25, 2026 at 08:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Elementor
Elementor website Builder
Wordpress
Wordpress wordpress
Vendors & Products Elementor
Elementor website Builder
Wordpress
Wordpress wordpress

Fri, 25 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.
Title WordPress Elementor Website Builder plugin <= 4.3.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Elementor Website Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-25T13:30:26.115Z

Reserved: 2026-07-13T06:14:43.014Z

Link: CVE-2026-62062

cve-icon Vulnrichment

Updated: 2026-09-25T13:30:09.237Z

cve-icon NVD

Status : Deferred

Published: 2026-09-25T07:16:54.010

Modified: 2026-09-25T14:17:18.807

Link: CVE-2026-62062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T09:00:14Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)