Elementor Patched a Security Flaw Found in Only Two of Its Versions

Elementor has fixed a security flaw that affects only two of its releases, and the update is already out. Patchstack's vulnerability database lists Elementor 4.3.0 and 4.3.1 as the affected versions and 4.3.2 as the patched one, so the step that matters for a site owner is checking which version the plugin is running. A site on any earlier release of the plugin is not affected.
WordPress.org's plugin directory lists the page builder on more than 10 million active installations and dates the fix to Sept. 24. Patchstack's database record classes the flaw as cross-site request forgery, meaning a logged-in user can be tricked into an action they did not intend. Its stated remedy is to update the plugin, or to ask a hosting provider or a web developer for help where that is not possible.
It labels the flaw medium priority and records a severity score of 8.8 under the standard CVSS scale, which its own page calls a repeatable way to rank vulnerabilities that is not ideal for WordPress. Both are the firm's own assessments, and it sells mitigation for the flaws it catalogs.
The record gives the identifier as CVE-2026-62062. That CVE entry carries a separate assessment from CISA's vulnerability enrichment program, which records no observed exploitation. Patchstack's page takes a different line, saying flaws of this kind are expected to become exploited and are used against large numbers of sites at once, which is the firm's expectation rather than an account of anything that has happened.
The firm published the record on Sept. 25 and credits the finding to a researcher named Saggre, reporting through the firm's bug bounty program.
