Impact
This vulnerability is a Cross‑Site Request Forgery flaw in the Elementor Website Builder plugin for WordPress. It could allow an attacker to trick an authenticated user into submitting requests to the site, potentially enabling unauthorized changes.
Affected Systems
The affected product is the WordPress Elementor Website Builder plugin provided by Elementor. All releases from the initial version up through 4.3.1 contain the flaw. Site administrators should verify the installed version and apply an update if necessary.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Inferred that exploitation requires an authenticated user and could be performed via a malicious webpage or other forged request techniques. Given the high CVSS, the risk is significant for sites with administrative users.
OpenCVE Enrichment