
CVE-2026-62062 के लिए प्रूफ-ऑफ-कॉन्सेप्ट और लैब पैक, जो Elementor 4.3.0-4.3.1 में एक अनधिकृत CSRF REST nonce बायपास है जो एडमिनिस्ट्रेटर खाता निर्माण को सक्षम बनाता है।
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-62062
WordPress — Elementor Website Builder 4.3.1 — Elementor
Elementor Website Builder में Cross-Site Request Forgery (CSRF) कमज़ोरी Cross Site Request Forgery की अनुमति देती है। यह समस्या Elementor Website Builder को प्रभावित करती है: n/a से 4.3.1 तक।
| CVE | CVE-2026-62062 · CVE.org |
| CWE | CWE-352 |
| CVSS | High: 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Product | Elementor Website Builder |
| Affected | सभी संस्करण 4.3.1 तक (सम्मिलित) |
| Patched | 4.3.2 और बाद के संस्करण |
| Auth | unauthenticated (स्रोत मैप देखें) |
| License | GNU Affero GPL v3.0 |
| Lab | केवल 127.0.0.1 · vendor/client disclosure pack, स्कैनर नहीं |
elementor/core/common/modules/events-manager/rest-api/events-proxy-rest-api.php is_own_route_request. 4.3.2 कच्चे REQUEST_URI के बजाय rest_route prefix का उपयोग करता है।
POST/?rest_route=/wp/v2/users&x=elementor/v1/events/victim admin has wordpress_logged_in cookiePOST /?rest_route=/wp/v2/users&x=elementor/v1/events/ JSON roles=administrator, no X-WP-NonceEvents_Proxy_REST_API.is_own_route_request strpos REQUEST_URIrest_authentication_errors returns true; rest_cookie_check_errors skips noncewp/v2/users create_item as the victim administratoradmin cookies के साथ और बिना nonce के POST: URI substring के बिना 401; x=elementor/v1/events/ के साथ 201 administrator user.
पहले यह करें: Elementor Website Builder को 4.3.2 या नए संस्करण में अपडेट करें।
अपग्रेड के बाद सत्यापित करें
CVE-2026-62062-Abraxas-Labs.py दोबारा चलाएँ: mapped witness नहीं दिखना चाहिए।यदि आप तुरंत अपडेट नहीं कर सकते
लक्ष्य केवल http://127.0.0.1:8088 (या जो loopback आपने bind किया है)। इस script को इंटरनेट पर न लक्षित करें।
python3 CVE-2026-62062-Abraxas-Labs.py
सफलता response body में ऊपर दिया गया witness है। सामान्य 200 HTML नहीं।
प्रतिलिपि के लिए उपयोग किया गया loopback stack। आधिकारिक images, जब तक इस फ़ोल्डर में Dockerfile स्रोत से build न करे।
cd lab
docker compose up --force-recreate
यदि YAML स्थानीय directory mount करता है तो vulnerable product tree को Compose के बगल में bind करें (version table से plugin zip / source tag)। 127.0.0.1 के अलावा कुछ publish न करें।
Plugin directory: elementor
Trac browser: plugins.trac.wordpress.org/elementor
SVN tags: plugins.svn.wordpress.org/elementor
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
# CVE-2026-62062
CWE: CWE-352
CVSS: High 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (Patchstack / Wordfence).
## Description
Elementor 4.3.0–4.3.1 skips WordPress REST cookie nonce validation when `$_SERVER['REQUEST_URI']` contains `elementor/v1/events/`. An unauthenticated attacker who tricks an administrator cookie session into requesting a REST URL with that substring can perform any REST action the victim’s role allows, including creating an administrator.
## Product
Elementor Website Builder 4.3.1 (fixed in 4.3.2). Free plugin on wordpress.org. Lab oracle is CSRF-style REST user create, not RCE.
यह disclosure pack GNU Affero General Public License v3.0 के अंतर्गत लाइसेंस प्राप्त है। देखें LICENSE।
यह pack vendor, site owner, और licensed labs के लिए है। Script 127.0.0.1 से बात करता है। जिन systems के आप मालिक नहीं हैं उनके विरुद्ध इसका उपयोग Abraxas Labs द्वारा अधिकृत नहीं है। कोई वारंटी नहीं।