
حزمة إثبات مفهوم ومختبر لـ CVE-2026-62062، وهو تجاوز CSRF REST nonce غير مصادق عليه في Elementor 4.3.0-4.3.1 يتيح إنشاء حساب مسؤول.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-62062
WordPress — Elementor Website Builder 4.3.1 — Elementor
ثغرة تزوير الطلب عبر المواقع (CSRF) في Elementor Website Builder تسمح بتزوير الطلب عبر المواقع. تؤثر هذه المشكلة على Elementor Website Builder: من n/a حتى 4.3.1.
| CVE | CVE-2026-62062 · CVE.org |
| CWE | CWE-352 |
| CVSS | High: 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Product | Elementor Website Builder |
| Affected | جميع الإصدارات حتى 4.3.1 (شاملة) |
| Patched | 4.3.2 وما بعده |
| Auth | بدون مصادقة (انظر خريطة المصدر) |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 فقط · حزمة إفصاح للمورّد/العميل، وليست ماسحًا ضوئيًا |
elementor/core/common/modules/events-manager/rest-api/events-proxy-rest-api.php is_own_route_request. يستخدم 4.3.2 بادئة rest_route بدلاً من REQUEST_URI الخام.
POST/?rest_route=/wp/v2/users&x=elementor/v1/events/victim admin has wordpress_logged_in cookiePOST /?rest_route=/wp/v2/users&x=elementor/v1/events/ JSON roles=administrator, no X-WP-NonceEvents_Proxy_REST_API.is_own_route_request strpos REQUEST_URIrest_authentication_errors returns true; rest_cookie_check_errors skips noncewp/v2/users create_item as the victim administratorPOST مع كوكيز المسؤول وبدون nonce: 401 بدون السلسلة الفرعية في URI؛ 201 مستخدم administrator مع x=elementor/v1/events/.
افعل هذا أولاً: حدّث Elementor Website Builder إلى 4.3.2 أو أحدث.
تحقق بعد الترقية
CVE-2026-62062-Abraxas-Labs.py مقابل البناء المرقّع: يجب ألا يظهر الشاهد المُعيَّن.إذا لم تستطع التحديث فورًا
استهدف فقط http://127.0.0.1:8088 (أو الـ loopback الذي ربطته). لا توجّه هذا السكربت إلى الإنترنت.
python3 CVE-2026-62062-Abraxas-Labs.py
النجاح هو الشاهد أعلاه في جسم الاستجابة. استجابة 200 HTML عامة ليست كذلك.
حزمة loopback المستخدمة لإعادة الإنتاج. صور رسمية ما لم يبنِ Dockerfile في هذا المجلد من المصدر.
cd lab
docker compose up --force-recreate
اربط شجرة المنتج المتأثر بجانب Compose إذا كان ملف YAML يربط دليلًا محليًا (plugin zip / source tag من جدول الإصدارات). لا تنشر شيئًا عدا 127.0.0.1.
دليل الإضافات: elementor
متصفح Trac: plugins.trac.wordpress.org/elementor
وسوم SVN: plugins.svn.wordpress.org/elementor
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
# CVE-2026-62062
CWE: CWE-352
CVSS: High 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (Patchstack / Wordfence).
## Description
Elementor 4.3.0–4.3.1 skips WordPress REST cookie nonce validation when `$_SERVER['REQUEST_URI']` contains `elementor/v1/events/`. An unauthenticated attacker who tricks an administrator cookie session into requesting a REST URL with that substring can perform any REST action the victim’s role allows, including creating an administrator.
## Product
Elementor Website Builder 4.3.1 (fixed in 4.3.2). Free plugin on wordpress.org. Lab oracle is CSRF-style REST user create, not RCE.
هذه الحزمة الإفصاحية مرخّصة بموجب GNU Affero General Public License v3.0. انظر LICENSE.
هذه الحزمة مخصّصة للمورّد، ومالك الموقع، والمختبرات المرخّصة. يتحدث السكربت إلى 127.0.0.1. استخدامه ضد أنظمة لا تملكها غير مصرّح به من Abraxas Labs. لا ضمان.