OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-62062

HIGH · CVSS 8.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Elementor Website Builder versions up to 4.3.1 are vulnerable to a Cross-Site Request Forgery (CSRF) attack, which could allow an attacker to perform unauthorized actions on behalf of authenticated users. This high-severity vulnerability poses a significant risk to websites using the affected versions, making it critical for web administrators and developers utilizing Elementor to prioritize immediate updates or mitigations.

CVE
CVE-2026-62062
Severity
HIGH
CVSS
8.8
EPSS
0.13%

Original NVD Description

Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.