Elementor shipped a fix on September 24 for a critical cross-site request forgery (CSRF) flaw in its free Website Builder plugin, tracked as CVE-2026-62062 with a CVSS score of 8.8. Versions 4.3.0 and 4.3.1 are affected, which together cover more than 2 million of Elementor’s roughly 10 million active installs. The bug let an attacker trick a logged-in administrator into creating a new admin account just by getting them to click a link. If you’re running one of the two affected versions, update to 4.3.2 today.
What the CSRF Flaw in Elementor 4.3.0 and 4.3.1 Actually Does
The flaw lives in Elementor’s Editor Events module, the part that proxies certain frontend interactions back to the server. According to Patchstack‘s coordinated disclosure with researcher Saggre, the module checks the raw request URL for the string elementor/v1/events/ and skips WordPress’s normal nonce validation whenever that string shows up anywhere in the URL, including inside the query string.
That’s the kind of shortcut that looks harmless until someone works out how to abuse it. An attacker can craft a link that points at the WordPress REST API’s /wp/v2/users endpoint while tacking the trigger string onto the query string, which makes the request look like a nonce-exempt Elementor event. If a logged-in administrator opens that link, their browser sends the request with their session cookies attached, and WordPress creates a new administrator account for the attacker. No password, no two-factor prompt, just one click from someone with access.
Beyond account creation, Patchstack’s writeup and WPScan’s listing both note the same nonce bypass opens the door to changing site options and deleting content, since it’s really a hole in CSRF protection for any REST action that can be made to carry the trigger string. A working proof-of-concept is already public on GitHub, so this isn’t a theoretical bug sitting in a research paper.
Who Needs to Act
This affects the free Elementor Website Builder plugin, not Elementor Pro, so it’s relevant even to sites that never bought the premium add-ons. If your Elementor version shows 4.3.0 or 4.3.1 in the plugins screen, update to 4.3.2 immediately. Sites on earlier 4.2.x or 4.1.x branches aren’t affected by this particular CVE, though it’s worth checking you’re not overdue on other Elementor patches while you’re in there, including the unauthenticated file upload flaw in Elementor Pro we covered back in August.
Because the exploit depends on a logged-in admin clicking a malicious link, the usual advice applies too: be suspicious of unexpected links in email, Slack, or comment notifications, especially ones that reference your own domain or admin area. It won’t stop a determined attacker, but it buys time while sites catch up on the update.
If you’re managing Elementor across client sites and patch cycles have been inconsistent, that’s exactly the kind of gap a WordPress and Elementor development partner catches before it turns into an incident report.



