
2ez. CVE-2026-62062 - WordPress - Elementor Website Builder - High 8.8 - CSRF to Administrator Account Creation. exploit... https://github.com/abraxas/CVE-2026-62062
Signal is active with 4 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

2ez. CVE-2026-62062 - WordPress - Elementor Website Builder - High 8.8 - CSRF to Administrator Account Creation. exploit... https://github.com/abraxas/CVE-2026-62062

🔴 WordPress Elementor Website Builder 4.3.0–4.3.1'de CVE-2026-62062 High (8.8) CSRF açığı için @abraxas_null tarafından PoC yayınlandı. Hatalı REQUEST_URI kontrolü, WordPress REST API nonce doğrulamasının bypass edilmesine yol açıyor. Yayınlanan PoC, saldırganın kimlik doğrulaması olmadan; oturum açmış bir yönetici kullanıcıyı kötü amaçlı isteğe yönlendirerek /wp/v2/users üzerinden yeni Administrator hesabı oluşturabildiğini gösteriyor. Etkilenen sürümler: ≤ 4.3.1 Düzeltilen sürüm: 4.3.2+ PoC: https://github.com/abraxas/CVE-2026-62062

@BleepinComputer check out the ascii art in the exploit https://github.com/abraxas/CVE-2026-62062

Elementor 4.3.0-4.3.1 CSRF flaw (CVE-2026-62062), fixed in 4.3.2. → One crafted link, opened by a logged-in admin, creates a new admin account → The bug disables WordPress's REST API nonce check for every REST route, not just Elementor's → CVSS 8.8, live for only about two days before the fix → Elementor Pro is affected too, since Pro runs on the free plugin's version → Fix: update Elementor to 4.3.2 https://magicwp.io/blog/elementor-4-3-csrf-vulnerability #WordPress #WordPressSecurity

@TweetThreatNews bleepbloop https://github.com/abraxas/CVE-2026-62062

@magicwp_io igotUfam https://github.com/abraxas/CVE-2026-62062

CVE-2026-62062:WordPress用Elementor 4.3.0~4.3.1のCSRF脆弱性。ログイン中の管理者に細工したリンクを開かせることで、不正な管理者アカウントを追加される可能性あり。9月25日には管理者追加まで可能な攻撃例が報告、4.3.2以降への更新を。 https://wordpress.org/plugins/elementor/#developers #脆弱性

🆕👉 Elementor 4.3.0-4.3.1 – REST Nonce Bypass to Privilege Escalation https://wpdeeply.com/elementor-4-3-0-4-3-1-rest-nonce-bypass-privilege-escalation-cve-2026-62062/ #loreleiweb Elementor Website Builder versions 4.3.0 and 4.3.1 contain a high-severity REST API nonce bypass that can turn a single clicked link into an administrator account takeove… https://t.co/ajNB4l1Nd4

WordPress用プラグインElementorの4.3.1以前にCSRFの脆弱性 — CVE-2026-62062はCVSS 8.8、修正版4.3.2が公開 https://cyber.nexsight.co/articles/2026/09/26/elementor-csrf-cve-2026-62062-fixed-4-3-2-2026-09-26/

🚨 Elementor Website Builder に脆弱性(深刻度 高) 1000万サイト以上が利用 / CVSS 8.8 修正版 4.3.2 が公開済み https://shindan.m-g-n.me/alerts/cve-2026-62062/

#Elementor esa cosa que usan los diseñadores web (sic) ha avisado de un CVE-2026-62062. Mis clientes parcheados. Buen finde.