LA-Studio Element Kit for Elementor <= 1.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 1.6.2
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2026
CVE-2026-65482 on NVD →
LA-Studio Element Kit for Elementor <= 1.6.2 - Missing Authorization
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.6.2
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2026
CVE-2026-65489 on NVD →
LA-Studio Element Kit for Elementor <= 1.6.2 - Cross-Site Request Forgery
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged reques...
- CVSS:
- 4.3
- Affected:
- up to 1.6.2
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2026
CVE-2026-65488 on NVD →
LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting
high
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on t...
- CVSS:
- 7.5
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.2
- Disclosed:
- Jul 10, 2026
CVE-2026-15338 on NVD →
LA-Studio Element Kit for Elementor <= 1.6.0 - Unauthenticated Open Registration
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to open registration in all versions up to, and including, 1.6.0. This is due to the plugin not properly check core options for site registration settings. This makes it possible for unauthenticated attackers to register on sites where it should...
- CVSS:
- 5.3
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.1
- Disclosed:
- Jun 19, 2026
CVE-2026-12276 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.5.6.3
unknown
[en] Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through < 1.5.6.3.
- Affected:
- up to 1.5.6.3
- Fixed in:
- 1.5.6.3
- Disclosed:
- Feb 3, 2026
CVE-2026-24947 on NVD →
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
critical
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.6.3. This is due to the 'ajax_register_handle' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to s...
- CVSS:
- 9.8
- Affected:
- up to 1.5.6.3
- Fixed in:
- 1.6.0
- Disclosed:
- Jan 21, 2026
CVE-2026-0920 on NVD →
LA-Studio Element Kit for Elementor < 1.5.6.3 - Missing Authorization
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 1.5.6.3 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.5.6.3
- Fixed in:
- 1.5.6.3
- Disclosed:
- Dec 15, 2025
CVE-2026-24947 on NVD →
LA-Studio Element Kit for Elementor <= 1.5.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets in all versions up to, and including, 1.5.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...
- CVSS:
- 6.4
- Affected:
- up to 1.5.5.1
- Fixed in:
- 1.5.5.2
- Disclosed:
- Sep 5, 2025
CVE-2025-8360 on NVD →
LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Compare and Google Maps Widgets
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Compare and Google Maps widgets in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...
- CVSS:
- 6.4
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.3
- Disclosed:
- May 29, 2025
CVE-2025-4944 on NVD →
LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-lakit-element-link’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contribut...
- CVSS:
- 6.4
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.3
- Disclosed:
- May 29, 2025
CVE-2025-4943 on NVD →
LA-Studio Element Kit for Elementor <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 1.4.9
- Fixed in:
- 1.5.0
- Disclosed:
- Apr 17, 2025
CVE-2025-3106 on NVD →
LA-Studio Element Kit for Elementor <= 1.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 1.5.1
- Fixed in:
- 1.5.2
- Disclosed:
- Apr 4, 2025
CVE-2025-32194 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.5.2
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Stored XSS. This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.4.9.
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Apr 4, 2025
CVE-2025-32194 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.1.6
unknown
[en] Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.1.5.
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- Dec 9, 2024
CVE-2023-50884 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.4.5
unknown
[en] The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.4 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor...
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Dec 4, 2024
CVE-2024-10787 on NVD →
LA-Studio Element Kit for Elementor <= 1.4.4 - Authenticated (Contributor+) Post Disclosure
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.4 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-leve...
- CVSS:
- 4.3
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.5
- Disclosed:
- Dec 3, 2024
CVE-2024-10787 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.4.3
unknown
[en] The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the _load_template function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the...
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Nov 23, 2024
CVE-2024-10873 on NVD →
LA-Studio Element Kit for Elementor <= 1.4.2 - Authenticated (Contributor+) Local File Inclusion
high
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the _load_template function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the serve...
- CVSS:
- 8.8
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- Nov 22, 2024
CVE-2024-10873 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.3.9.7
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Stored XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.9.3.
- Affected:
- up to 1.3.9.7
- Fixed in:
- 1.3.9.7
- Disclosed:
- Oct 5, 2024
CVE-2024-47628 on NVD →
LA-Studio Element Kit for Elementor <= 1.3.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- up to 1.3.9.3
- Fixed in:
- 1.3.9.7
- Disclosed:
- Sep 30, 2024
CVE-2024-47628 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.3.9.3
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Stored XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.9.2.
- Affected:
- up to 1.3.9.3
- Fixed in:
- 1.3.9.3
- Disclosed:
- Aug 12, 2024
CVE-2024-43210 on NVD →
LA-Studio Element Kit for Elementor <= 1.3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.9.2 due to insufficient input sanitization and output escaping on title tags found in blocks. This makes it possible for authenticated attackers, with contributor-level access...
- CVSS:
- 6.4
- Affected:
- up to 1.3.9.2
- Fixed in:
- 1.3.9.3
- Disclosed:
- Aug 9, 2024
CVE-2024-43210 on NVD →
LA-Studio Element Kit for Elementor <= 1.3.8.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type'
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'progress_type' attribute of the Progress Bar widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execu...
- CVSS:
- 5.4
- Affected:
- up to 1.3.8.1
- Fixed in:
- 1.3.9
- Disclosed:
- Jul 2, 2024
CVE-2024-37479 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.3.9
unknown
[en] The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'map_style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the...
- Affected:
- up to 1.3.9
- Fixed in:
- 1.3.9
- Disclosed:
- Jul 2, 2024
CVE-2024-5349 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.3.9
unknown
[en] Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically in the "progress_type" attribute.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.8.1.
- Affected:
- up to 1.3.9
- Fixed in:
- 1.3.9
- Disclosed:
- Jul 2, 2024
CVE-2024-37479 on NVD →
LA-Studio Element Kit for Elementor <= 1.3.8.1 - Authenticated (Contributor+) Local File Inclusion
high
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'map_style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the serve...
- CVSS:
- 8.8
- Affected:
- up to 1.3.8.1
- Fixed in:
- 1.3.9
- Disclosed:
- Jul 1, 2024
CVE-2024-5349 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.3.7.4
unknown
[en] Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.6.
- Affected:
- up to 1.3.7.4
- Fixed in:
- 1.3.7.4
- Disclosed:
- Jun 10, 2024
CVE-2024-35725 on NVD →
LA-Studio Element Kit for Elementor <= 1.3.6 - Missing Authorization
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.7.4
- Disclosed:
- Jun 6, 2024
CVE-2024-35725 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.3.8
unknown
[en] The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acces...
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.8
- Disclosed:
- May 23, 2024
CVE-2024-4431 on NVD →
LA-Studio Element Kit for Elementor <= 1.3.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and...
- CVSS:
- 6.4
- Affected:
- up to 1.3.7.6
- Fixed in:
- 1.3.8
- Disclosed:
- May 22, 2024
CVE-2024-4431 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.3.7.6
unknown
[en] The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's LaStudioKit Post Author widget in all versions up to, and including, 1.3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...
- Affected:
- up to 1.3.7.6
- Fixed in:
- 1.3.7.6
- Disclosed:
- May 2, 2024
CVE-2024-3005 on NVD →
LA-Studio Element Kit for Elementor <= 1.3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via LaStudioKit Post Author Widget
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's LaStudioKit Post Author widget in all versions up to, and including, 1.3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe...
- CVSS:
- 6.4
- Affected:
- up to 1.3.7.5
- Fixed in:
- 1.3.7.6
- Disclosed:
- May 1, 2024
CVE-2024-3005 on NVD →
LA-Studio Element Kit for Elementor <= 1.3.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWrapper attribute found in several widgets in all versions up to, and including, 1.3.7.4 due to insufficient input sanitization and output escaping the user supplied attribute. This makes it possible fo...
- CVSS:
- 6.4
- Affected:
- up to 1.3.7.4
- Fixed in:
- 1.3.7.5
- Disclosed:
- Mar 14, 2024
CVE-2024-2249 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.3.7.5
unknown
[en] The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWrapper attribute found in several widgets in all versions up to, and including, 1.3.7.4 due to insufficient input sanitization and output escaping the user supplied attribute. This makes it possib...
- Affected:
- up to 1.3.7.5
- Fixed in:
- 1.3.7.5
- Disclosed:
- Mar 14, 2024
CVE-2024-2249 on NVD →
LA-Studio Element Kit for Elementor <= 1.1.5 - Missing Authorization
medium
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a REST-API endpoint in versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to update the plugin's settings.
- CVSS:
- 5.3
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.6
- Disclosed:
- Dec 26, 2023
CVE-2023-50884 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] <= 1.3.9.2 (unfixed)
unknown
- Affected:
- up to 1.3.9.2
- Fix:
- No patched version reported
LA-Studio Element Kit for Elementor [lastudio-element-kit] <= 1.3.9.2 (unfixed)
unknown
- Affected:
- up to 1.3.9.2
- Fix:
- No patched version reported
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.5.0
unknown
- Affected:
- up to 1.5.0
- Fixed in:
- 1.5.0
CVE-2025-3106 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.5.3
unknown
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
CVE-2025-4944 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.5.3
unknown
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
CVE-2025-4943 on NVD →
LA-Studio Element Kit for Elementor [lastudio-element-kit] < 1.5.5.2
unknown
- Affected:
- up to 1.5.5.2
- Fixed in:
- 1.5.5.2
CVE-2025-8360 on NVD →