{"id":"CVE-2026-62062","published":"2026-09-25T07:16:54.010","lastModified":"2026-09-25T14:17:18.807","description":"Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery.\n\nThis issue affects Elementor Website Builder: from n/a through 4.3.1.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-352"],"vendors":[],"products":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/elementor/vulnerability/wordpress-elementor-website-builder-plugin-4-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"A Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows attackers to forge requests that the victim has authorized, potentially leading to unauthorized actions on the victim's behalf.","exploitability":"Exploitation is relatively easy given that the victim must be logged in and tricked into performing an action on the attacker's behalf. The attacker needs control over a web page that the victim visits.","blast_radius":"If exploited, the impact could be high, as it allows attackers to perform actions on behalf of the victim, potentially leading to data loss, account compromise, or other harmful actions.","remediation":"Upgrade to Elementor Website Builder 4.3.2 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["csrf","web","auth-bypass"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:04:09.675Z"}}