BlackTree Security · Infrastructure · Automation · AI

One Link Could Make Your WordPress Admin Create the Attacker’s Account

Patchstack has demonstrated how one crafted link can make a logged-in WordPress administrator create an attacker-controlled admin account. The affected Elementor Website Builder releases are 4.3.0 and 4.3.1; version 4.3.2 fixes the issue.

The vulnerability record identifies CVE-2026-62062 as a CVSS 8.8 cross-site request forgery flaw. The attacker needs no site account, but the victim must already be logged in with sufficient permissions.

The browser carries authority without proof of intent

The technical analysis describes a check that trusts the string elementor/v1/events/ anywhere in a request URI. An attacker-controlled query can therefore bypass the normal REST nonce check. Other authorised REST routes are in scope, not only Elementor routes. The hidden component defaults on for sites first installed with Elementor 3.32.0 or later. The reviewed disclosure does not confirm malicious exploitation.

An extra administrator can outlast the patch

For a site owner, the important distinction is between closing the request path and removing changes already made through it. Updating a plugin does not itself explain who created each administrator, whether credentials were changed or which settings were altered. Record those questions in the incident review instead of treating a successful update screen as proof that the site is clean.

Agencies managing many customer sites should verify the installed release on each site and assign responsibility for account review. A shared maintenance account can otherwise obscure which person was browsing when a suspicious request occurred.

What WordPress administrators should do

  • Update Elementor to 4.3.2 or later. Confirm the version after the update, including staging and dormant sites.
  • Review administrator accounts. Look for unexpected users created while 4.3.0 or 4.3.1 was installed, and confirm creation times and email addresses.
  • Inspect REST and web logs. Search for requests containing elementor/v1/events/ in a query string, especially requests to user, settings or plugin endpoints.
  • Invalidate suspicious sessions. If an administrator may have opened a crafted link, rotate affected credentials and authentication salts after preserving evidence.
  • Reduce routine admin browsing. Use separate accounts or browser profiles for administration and general email or web use.
  • Check connected plugins. The bypass can carry the victim’s authority into other REST routes, so the review should not stop at Elementor endpoints.

BlackTree previously covered a separate Elementor Pro file-upload vulnerability. That issue and CVE-2026-62062 are not the same flaw. The new lesson is about shared authentication hooks: code intended to exempt one plugin route can accidentally assert trust for the entire REST surface.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *