Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

LA-Studio — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting LA-Studio. AI-powered Chinese analysis, POCs, and references for each vulnerability.

LA-Studio is a web-based application primarily used for digital content creation and management. Historically, it has been vulnerable to multiple remote code execution (RCE) and cross-site scripting (XSS) flaws, often stemming from insufficient input validation. Several privilege escalation vulnerabilities have also been documented, allowing unauthorized access to administrative functions. With seven CVEs currently recorded, the application has faced persistent security challenges, including incidents where attackers could execute arbitrary code or compromise user sessions. Its security posture has been characterized by consistent vulnerabilities in authentication mechanisms and file handling processes, requiring regular patching and hardening to mitigate risks.

Top products by LA-Studio: LA-Studio Element Kit for Elementor
CVE IDTitleCVSSSeverityPublished
CVE-2026-65488 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability — LA-Studio Element Kit for ElementorCWE-352 7.1 High2026-07-23
CVE-2026-65489 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Broken Access Control vulnerability — LA-Studio Element Kit for ElementorCWE-862 5.3 Medium2026-07-23
CVE-2026-65482 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerability — LA-Studio Element Kit for ElementorCWE-79 6.5 Medium2026-07-23
CVE-2026-24947 WordPress LA-Studio Element Kit for Elementor plugin < 1.5.6.3 - Broken Access Control vulnerability — LA-Studio Element Kit for ElementorCWE-862 4.3 Medium2026-02-03
CVE-2025-32194 WordPress LA-Studio Element Kit for Elementor plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability — LA-Studio Element Kit for ElementorCWE-79 6.5 Medium2025-04-04
CVE-2023-50884 WordPress LA-Studio Element Kit for Elementor plugin <= 1.1.5 - Broken Access Control vulnerability — LA-Studio Element Kit for ElementorCWE-862 6.5 Medium2024-12-09
CVE-2024-47628 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.9.3 - Cross Site Scripting (XSS) vulnerability — LA-Studio Element Kit for ElementorCWE-79 6.5 Medium2024-10-05
CVE-2024-43210 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.9.2 - Cross Site Scripting (XSS) vulnerability — LA-Studio Element Kit for ElementorCWE-79 6.5 Medium2024-08-12
CVE-2024-37479 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.8.1 - Contributor+ Local File Inclusion vulnerability — LA-Studio Element Kit for Elementor 8.5 High2024-07-02
CVE-2024-35725 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.6 - Broken Access Control vulnerability — LA-Studio Element Kit for ElementorCWE-862 4.3 Medium2024-06-10

This page lists every published CVE security advisory associated with LA-Studio. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.