Elementor WordPress plugin CSRF flaw allows unauthorized admin account creation

A critical cross-site request forgery (CSRF) vulnerability in the Elementor Website Builder plugin for WordPress (versions 4.3.1 and earlier) was disclosed on September 25, 2026, allowing unauthenticated attackers to create administrator accounts. The vulnerability was patched in an updated version, and administrators were urged to update immediately.

5 reports · 4 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-62062 - WordPress Elementor Website Builder plugin <= 4.3.1 - Cross Site Request Forgery (CSRF) vulnerability

stream:bsky-jetstreamother4d ago kagi ↗

CVE-2026-62062 - WordPress Elementor Website Builder plugin CVE ID : CVE-2026-62062 Published : Sept. 25, 2026, 6:29 a.m. | 29 minutes ago Description : Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This ... Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue aff

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. https://www. bleepingcomputer.com/news

mastodon:infosec-exchangeother4d ago kagi ↗

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. https://www. bleepingcomputer.com/news/secu rity/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/

🤖 CSRF vulnerability patched in the Elementor WordPress plugin allows unauthenticated attackers to create administrator accounts on affected sites. Admins should update to the latest version. 🔗 http

mastodon:infosec-exchangeother4d ago kagi ↗

🤖 CSRF vulnerability patched in the Elementor WordPress plugin allows unauthenticated attackers to create administrator accounts on affected sites. Admins should update to the latest version. 🔗 https://www. bleepingcomputer.com/news/secu rity/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/ # WordPress # CSRF # CyberSec