abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-62062
WordPress — Elementor Website Builder 4.3.1 — Elementor
Elementor Website Builder 中的跨站请求伪造(CSRF)漏洞允许跨站请求伪造。此问题影响 Elementor Website Builder:从 n/a 到 4.3.1 的所有版本。
| CVE | CVE-2026-62062 · CVE.org |
| CWE | CWE-352 |
| CVSS | High: 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 产品 | Elementor Website Builder |
| 受影响版本 | 所有版本 直至 4.3.1(含) |
| 已修复版本 | 4.3.2 及更高版本 |
| 认证 | 未认证(见 source map) |
| 许可证 | GNU Affero GPL v3.0 |
| 实验室 | 仅限 127.0.0.1 · 供应商/客户披露包,非扫描器 |
elementor/core/common/modules/events-manager/rest-api/events-proxy-rest-api.php is_own_route_request。4.3.2 使用 rest_route 前缀而非原始 REQUEST_URI。
POST/?rest_route=/wp/v2/users&x=elementor/v1/events/victim admin has wordpress_logged_in cookiePOST /?rest_route=/wp/v2/users&x=elementor/v1/events/ JSON roles=administrator, no X-WP-NonceEvents_Proxy_REST_API.is_own_route_request strpos REQUEST_URIrest_authentication_errors returns true; rest_cookie_check_errors skips noncewp/v2/users create_item as the victim administrator使用管理员 cookie 且不带 nonce 的 POST:不带 URI 子串时返回 401;带 x=elementor/v1/events/ 时返回 201 管理员用户。
首先执行: 将 Elementor Website Builder 更新至 4.3.2 或更高版本。
升级后验证
CVE-2026-62062-Abraxas-Labs.py:映射的见证必须不出现。如果无法立即更新
仅针对 http://127.0.0.1:8088(或你绑定的回环地址)。不要将此脚本指向互联网。
python3 CVE-2026-62062-Abraxas-Labs.py
成功即响应体中出现上述见证。通用的 200 HTML 不算。
用于复现的回环栈。除非此文件夹中的 Dockerfile 从源码构建,否则使用官方镜像。
cd lab
docker compose up --force-recreate
如果 YAML 挂载本地目录(来自版本表的插件 zip / 源码标签),请将易受攻击的产品目录树绑定到 Compose 旁边。除 127.0.0.1 外不要发布任何内容。
插件目录:elementor
Trac 浏览器:plugins.trac.wordpress.org/elementor
Abraxas Labs:abraxaslabs.tech · github.com/abraxas · @abraxas_null
# CVE-2026-62062
CWE: CWE-352
CVSS: High 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (Patchstack / Wordfence).
## Description
Elementor 4.3.0–4.3.1 skips WordPress REST cookie nonce validation when `$_SERVER['REQUEST_URI']` contains `elementor/v1/events/`. An unauthenticated attacker who tricks an administrator cookie session into requesting a REST URL with that substring can perform any REST action the victim’s role allows, including creating an administrator.
## Product
Elementor Website Builder 4.3.1 (fixed in 4.3.2). Free plugin on wordpress.org. Lab oracle is CSRF-style REST user create, not RCE.
本披露包依据 GNU Affero General Public License v3.0 许可。见 LICENSE。
本包面向供应商、站点所有者及授权实验室。该脚本仅与 127.0.0.1 通信。将其用于你并不拥有的系统未获 Abraxas Labs 授权。不提供任何担保。