Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

LA-Studio Element Kit for Elementor — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in LA-Studio Element Kit for Elementor, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability reports for LA-Studio Element Kit for Elementor, a third-party plugin for the WordPress page builder, focusing on specific security weaknesses and associated tags. It collects known security flaws, including privilege escalation, cross-site scripting, and SQL injection vulnerabilities, covering disclosures from the plugin's initial release through the most recent audit cycles. Readers can use this hub to track the vendor’s advisory history, understand the technical nature of each weakness class, and review the complete vulnerability timeline for this product. The data helps developers and security teams identify recurring patterns in the codebase, assess exposure across WordPress sites using the kit, and correlate new findings with previously patched issues. By centralizing these records, the page supports impact analysis and remediation planning without requiring users to search multiple individual advisory feeds.

Vendor: choijun

CVE ID Title CVSS Severity Published
CVE-2026-103082 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability CWE-918 7.2 High 2026-10-01
CVE-2026-65489 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Broken Access Control vulnerability CWE-862 5.3 Medium 2026-07-23
CVE-2026-65488 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability CWE-352 7.1 High 2026-07-23
CVE-2026-65482 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.3 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-07-23
CVE-2026-15338 LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting CWE-98 7.5 High 2026-07-11
CVE-2026-12276 LA-Studio Element Kit for Elementor < 1.6.1 - Unauthenticated Open Registration - - 2026-07-10
CVE-2026-24947 WordPress LA-Studio Element Kit for Elementor plugin < 1.5.6.3 - Broken Access Control vulnerability CWE-862 4.3 Medium 2026-02-03
CVE-2026-0920 LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter CWE-269 9.8 Critical 2026-01-22
CVE-2025-8360 LA-Studio Element Kit for Elementor <= 1.5.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets CWE-79 6.4 Medium 2025-09-06
CVE-2025-4944 LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Compare and Google Maps Widgets CWE-79 6.4 Medium 2025-05-30
CVE-2025-4943 LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter CWE-79 6.4 Medium 2025-05-30
CVE-2025-3106 LA-Studio Element Kit for Elementor <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget CWE-79 6.4 Medium 2025-04-18
CVE-2025-32194 WordPress LA-Studio Element Kit for Elementor plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-04-04
CVE-2023-50884 WordPress LA-Studio Element Kit for Elementor plugin <= 1.1.5 - Broken Access Control vulnerability CWE-862 6.5 Medium 2024-12-09
CVE-2024-10787 LA-Studio Element Kit for Elementor <= 1.4.4 - Authenticated (Contributor+) Post Disclosure CWE-639 4.3 Medium 2024-12-04
CVE-2024-10873 LA-Studio Element Kit for Elementor <= 1.4.2 - Authenticated (Contributor+) Local File Inclusion CWE-98 8.8 High 2024-11-23
CVE-2024-47628 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.9.3 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-10-05
CVE-2024-43210 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.9.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-08-12
CVE-2024-37479 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.8.1 - Contributor+ Local File Inclusion vulnerability 8.5 High 2024-07-02
CVE-2024-5349 LA-Studio Element Kit for Elementor <= 1.3.8.1 - Authenticated (Contributor+) Local File Inclusion CWE-22 8.8 High 2024-07-02
CVE-2024-35725 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.6 - Broken Access Control vulnerability CWE-862 4.3 Medium 2024-06-10
CVE-2024-4431 LA-Studio Element Kit for Elementor <= 1.3.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter CWE-79 6.4 Medium 2024-05-23
CVE-2024-3005 LA-Studio Element Kit for Elementor <= 1.3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via LaStudioKit Post Author Widget CWE-79 6.4 Medium 2024-05-02
CVE-2024-2249 LA-Studio Element Kit for Elementor <= 1.3.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-03-14

All 24 known CVE vulnerabilities affecting LA-Studio Element Kit for Elementor with full Chinese analysis, references, and POCs where available.