cross-posted from: https://lemmy.world/post/52400011
A new Elementor vulnerability, CVE-2026-62062, affects versions 4.3.0 and 4.3.1 and carries a CVSS score of 8.8. Elementor’s Editor Events module checks the raw REQUEST_URI for the string elementor/v1/events/. Because REQUEST_URI includes the query string, an attacker can place that string inside a parameter and cause Elementor’s nonce-bypass logic to apply to requests that are actually targeting other WordPress REST API endpoints. The result is a CSRF protection bypass that can potentially be used against privileged REST API actions. The published attack scenario involves tricking a logged-in administrator into clicking a crafted link that can create a rogue administrator account.
You must log in or # to comment.


