
Proof-of-concept e pacchetto lab per CVE-2026-62062, un bypass del nonce REST CSRF non autenticato in Elementor 4.3.0-4.3.1 che consente la creazione di account amministratore.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-62062
WordPress — Elementor Website Builder 4.3.1 — Elementor
Una vulnerabilità di Cross-Site Request Forgery (CSRF) in Elementor Website Builder consente il Cross Site Request Forgery. Questo problema riguarda Elementor Website Builder: dalla versione n/a fino alla 4.3.1.
| CVE | CVE-2026-62062 · CVE.org |
| CWE | CWE-352 |
| CVSS | High: 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Prodotto | Elementor Website Builder |
| Affette | tutte le versioni fino alla 4.3.1 (inclusa) |
| Corrette | 4.3.2 e successive |
| Auth | non autenticato (vedi source map) |
| Licenza | GNU Affero GPL v3.0 |
| Lab | solo 127.0.0.1 · pacchetto di disclosure per vendor/client, non uno scanner |
elementor/core/common/modules/events-manager/rest-api/events-proxy-rest-api.php is_own_route_request. La 4.3.2 usa il prefisso rest_route invece del REQUEST_URI grezzo.
POST/?rest_route=/wp/v2/users&x=elementor/v1/events/victim admin has wordpress_logged_in cookiePOST /?rest_route=/wp/v2/users&x=elementor/v1/events/ JSON roles=administrator, no X-WP-NonceEvents_Proxy_REST_API.is_own_route_request strpos REQUEST_URIrest_authentication_errors returns true; rest_cookie_check_errors skips noncewp/v2/users create_item as the victim administratorPOST con cookie di amministratore e senza nonce: 401 senza la sottostringa URI; 201 utente amministratore con x=elementor/v1/events/.
Fai questo per primo: Aggiorna Elementor Website Builder alla 4.3.2 o successiva.
Verifica dopo l'aggiornamento
CVE-2026-62062-Abraxas-Labs.py contro la build corretta: il witness mappato non deve comparire.Se non puoi aggiornare immediatamente
Prendi di mira solo http://127.0.0.1:8088 (o il loopback su cui ti sei associato). Non puntare questo script verso Internet.
python3 CVE-2026-62062-Abraxas-Labs.py
Il successo è il witness sopra nel corpo della risposta. Un generico 200 HTML non lo è.
Stack loopback usato per la riproduzione. Immagini ufficiali a meno che un Dockerfile in questa cartella non venga compilato dai sorgenti.
cd lab
docker compose up --force-recreate
Associa l'albero del prodotto vulnerabile accanto a Compose se lo YAML monta una directory locale (zip del plugin / tag sorgente dalla tabella delle versioni). Non pubblicare nulla tranne 127.0.0.1.
Directory dei plugin: elementor
Browser Trac: plugins.trac.wordpress.org/elementor
Tag SVN: plugins.svn.wordpress.org/elementor
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
# CVE-2026-62062
CWE: CWE-352
CVSS: High 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (Patchstack / Wordfence).
## Description
Elementor 4.3.0–4.3.1 skips WordPress REST cookie nonce validation when `$_SERVER['REQUEST_URI']` contains `elementor/v1/events/`. An unauthenticated attacker who tricks an administrator cookie session into requesting a REST URL with that substring can perform any REST action the victim’s role allows, including creating an administrator.
## Product
Elementor Website Builder 4.3.1 (fixed in 4.3.2). Free plugin on wordpress.org. Lab oracle is CSRF-style REST user create, not RCE.
Questo pacchetto di disclosure è concesso in licenza sotto la GNU Affero General Public License v3.0. Vedi LICENSE.
Questo pacchetto è destinato al vendor, al proprietario del sito e ai lab autorizzati. Lo script comunica con 127.0.0.1. Usarlo contro sistemi che non possiedi non è autorizzato da Abraxas Labs. Nessuna garanzia.