Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

LA-Studio — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting LA-Studio. AI-powered Chinese analysis, POCs, and references for each vulnerability.

LA-Studio is a web-based application primarily used for digital content creation and management. Historically, it has been vulnerable to multiple remote code execution (RCE) and cross-site scripting (XSS) flaws, often stemming from insufficient input validation. Several privilege escalation vulnerabilities have also been documented, allowing unauthorized access to administrative functions. With seven CVEs currently recorded, the application has faced persistent security challenges, including incidents where attackers could execute arbitrary code or compromise user sessions. Its security posture has been characterized by consistent vulnerabilities in authentication mechanisms and file handling processes, requiring regular patching and hardening to mitigate risks.

Top products by LA-Studio: LA-Studio Element Kit for Elementor
CVE ID Title CVSS Severity Published
CVE-2026-103082 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability — LA-Studio Element Kit for Elementor CWE-918 7.2 High 2026-10-01
CVE-2026-65488 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability — LA-Studio Element Kit for Elementor CWE-352 7.1 High 2026-07-23
CVE-2026-65489 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Broken Access Control vulnerability — LA-Studio Element Kit for Elementor CWE-862 5.3 Medium 2026-07-23
CVE-2026-65482 WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.3 - Cross Site Scripting (XSS) vulnerability — LA-Studio Element Kit for Elementor CWE-79 6.5 Medium 2026-07-23
CVE-2026-24947 WordPress LA-Studio Element Kit for Elementor plugin < 1.5.6.3 - Broken Access Control vulnerability — LA-Studio Element Kit for Elementor CWE-862 4.3 Medium 2026-02-03
CVE-2025-32194 WordPress LA-Studio Element Kit for Elementor plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability — LA-Studio Element Kit for Elementor CWE-79 6.5 Medium 2025-04-04
CVE-2023-50884 WordPress LA-Studio Element Kit for Elementor plugin <= 1.1.5 - Broken Access Control vulnerability — LA-Studio Element Kit for Elementor CWE-862 6.5 Medium 2024-12-09
CVE-2024-47628 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.9.3 - Cross Site Scripting (XSS) vulnerability — LA-Studio Element Kit for Elementor CWE-79 6.5 Medium 2024-10-05
CVE-2024-43210 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.9.2 - Cross Site Scripting (XSS) vulnerability — LA-Studio Element Kit for Elementor CWE-79 6.5 Medium 2024-08-12
CVE-2024-37479 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.8.1 - Contributor+ Local File Inclusion vulnerability — LA-Studio Element Kit for Elementor 8.5 High 2024-07-02
CVE-2024-35725 WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.6 - Broken Access Control vulnerability — LA-Studio Element Kit for Elementor CWE-862 4.3 Medium 2024-06-10

This page lists every published CVE security advisory associated with LA-Studio. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.