Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

LA-Studio Element Kit for Elementor — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in LA-Studio Element Kit for Elementor, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses affecting the LA-Studio Element Kit for Elementor plugin, categorized under common weakness enumeration tags. It aggregates a comprehensive collection of vulnerabilities discovered within this specific WordPress extension, covering incidents reported from its initial release through the present day. By consulting this resource, users and security professionals can effectively track vendor advisories as they are issued, gain a deeper understanding of specific weakness classes and their exploitation vectors, and review the complete vulnerability history of the product to assess long-term security posture. The data is organized to facilitate easy navigation, allowing stakeholders to identify critical flaws, monitor patch adoption, and understand the evolving threat landscape surrounding this popular page builder addon. This centralized approach ensures that administrators can make informed decisions regarding updates and risk mitigation strategies without needing to scour multiple disparate sources for information. All entries are sourced from official advisories and verified public disclosures to maintain accuracy and reliability. The goal is to provide a transparent and accessible repository of security intelligence that supports the broader WordPress community in maintaining a safer digital ecosystem. Readers are encouraged to use this information to prioritize remediation efforts and enhance the overall resilience of their websites against potential compromises linked to this plugin.

Vendor: choijun

CVE IDTitleCVSSSeverityPublished
CVE-2026-65489 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Broken Access Control vulnerability CWE-862 5.3 Medium2026-07-23
CVE-2026-65488 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability CWE-352 7.1 High2026-07-23
CVE-2026-65482 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2026-07-23
CVE-2026-15338 LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting CWE-98 7.5 High2026-07-11
CVE-2026-12276 LA-Studio Element Kit for Elementor < 1.6.1 - Unauthenticated Open Registration --2026-07-10
CVE-2026-24947 WordPress LA-Studio Element Kit for Elementor plugin < 1.5.6.3 - Broken Access Control vulnerability CWE-862 4.3 Medium2026-02-03
CVE-2026-0920 LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter CWE-269 9.8 Critical2026-01-22
CVE-2025-8360 LA-Studio Element Kit for Elementor <= 1.5.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets CWE-79 6.4 Medium2025-09-06
CVE-2025-4944 LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Compare and Google Maps Widgets CWE-79 6.4 Medium2025-05-30
CVE-2025-4943 LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter CWE-79 6.4 Medium2025-05-30
CVE-2025-3106 LA-Studio Element Kit for Elementor <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget CWE-79 6.4 Medium2025-04-18
CVE-2025-32194 WordPress LA-Studio Element Kit for Elementor plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2025-04-04
CVE-2023-50884 WordPress LA-Studio Element Kit for Elementor plugin <= 1.1.5 - Broken Access Control vulnerability CWE-862 6.5 Medium2024-12-09
CVE-2024-10787 LA-Studio Element Kit for Elementor <= 1.4.4 - Authenticated (Contributor+) Post Disclosure CWE-639 4.3 Medium2024-12-04
CVE-2024-10873 LA-Studio Element Kit for Elementor <= 1.4.2 - Authenticated (Contributor+) Local File Inclusion CWE-98 8.8 High2024-11-23
CVE-2024-47628 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.9.3 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-10-05
CVE-2024-43210 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.9.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-08-12
CVE-2024-37479 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.8.1 - Contributor+ Local File Inclusion vulnerability 8.5 High2024-07-02
CVE-2024-5349 LA-Studio Element Kit for Elementor <= 1.3.8.1 - Authenticated (Contributor+) Local File Inclusion CWE-22 8.8 High2024-07-02
CVE-2024-35725 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.6 - Broken Access Control vulnerability CWE-862 4.3 Medium2024-06-10
CVE-2024-4431 LA-Studio Element Kit for Elementor <= 1.3.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter CWE-79 6.4 Medium2024-05-23
CVE-2024-3005 LA-Studio Element Kit for Elementor <= 1.3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via LaStudioKit Post Author Widget CWE-79 6.4 Medium2024-05-02
CVE-2024-2249 LA-Studio Element Kit for Elementor <= 1.3.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-03-14

All 23 known CVE vulnerabilities affecting LA-Studio Element Kit for Elementor with full Chinese analysis, references, and POCs where available.