LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor has 23 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; 20 are fixed and 3 remain unpatched as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 3 high. 2024 was the busiest year with 10 disclosures.

The most common weakness is Cross-Site Scripting, behind 11 of the records (48%). Other recurring categories include Missing Authorization, PHP Remote File Inclusion.

20 of the records (87%) have a vendor fix, while 3 remain unpatched. The oldest unresolved one dates back to 2026.

18 independent researchers contributed these findings, most of them (2) reported by Francesco Carlucci. LA-Studio Element Kit for Elementor is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.0.

01234567891024.03.2021Today26.12.20235.3LA-Studio Element Kit for Elementor <= 1.1.5 - Missing Authorization CVSS 5.3 · 26.12.202314.03.20246.4LA-Studio Element Kit for Elementor <= 1.3.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 14.03.202401.05.20246.4LA-Studio Element Kit for Elementor <= 1.3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via LaStudioKit Post Author Widget CVSS 6.4 · 01.05.202422.05.20246.4LA-Studio Element Kit for Elementor <= 1.3.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter CVSS 6.4 · 22.05.202406.06.20245.3LA-Studio Element Kit for Elementor <= 1.3.6 - Missing Authorization CVSS 5.3 · 06.06.202401.07.20248.8LA-Studio Element Kit for Elementor <= 1.3.8.1 - Authenticated (Contributor+) Local File Inclusion CVSS 8.8 · 01.07.202402.07.20245.4LA-Studio Element Kit for Elementor <= 1.3.8.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' CVSS 5.4 · 02.07.202409.08.20246.4LA-Studio Element Kit for Elementor <= 1.3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 09.08.202430.09.20246.4LA-Studio Element Kit for Elementor <= 1.3.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 30.09.202422.11.20248.8LA-Studio Element Kit for Elementor <= 1.4.2 - Authenticated (Contributor+) Local File Inclusion CVSS 8.8 · 22.11.202403.12.20244.3LA-Studio Element Kit for Elementor <= 1.4.4 - Authenticated (Contributor+) Post Disclosure CVSS 4.3 · 03.12.202404.04.20256.4LA-Studio Element Kit for Elementor <= 1.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 04.04.202517.04.20256.4LA-Studio Element Kit for Elementor <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget CVSS 6.4 · 17.04.202529.05.20256.4LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter CVSS 6.4 · 29.05.20256.4LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Compare and Google Maps Widgets CVSS 6.4 · 29.05.202505.09.20256.4LA-Studio Element Kit for Elementor <= 1.5.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets CVSS 6.4 · 05.09.202515.12.20255.3LA-Studio Element Kit for Elementor < 1.5.6.3 - Missing Authorization CVSS 5.3 · 15.12.202521.01.20269.8LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter CVSS 9.8 · 21.01.202619.06.20265.3LA-Studio Element Kit for Elementor <= 1.6.0 - Unauthenticated Open Registration CVSS 5.3 · 19.06.202610.07.20267.5LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting CVSS 7.5 · 10.07.202622.07.20264.3LA-Studio Element Kit for Elementor <= 1.6.2 - Cross-Site Request Forgery CVSS 4.3 · 22.07.20265.3LA-Studio Element Kit for Elementor <= 1.6.2 - Missing Authorization CVSS 5.3 · 22.07.20266.4LA-Studio Element Kit for Elementor <= 1.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 22.07.2026

Strategic Overview

Avg CVSSMedium
6.3/ 10
Patch Coverage87%
Open

3

Fixed

20

Get automatic notifications for all LA-Studio Element Kit for Elementor vulnerabilities before they are exploited.

Most severe open issueCVSS 6.4CVE-2026-65482

LA-Studio Element Kit for Elementor <= 1.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

23 records
2026-07-22 00:00CVE-2026-65488
4.3
Medium
Steven JulianNo
2026-07-22 00:00CVE-2026-65489
5.3
Medium
Steven JulianNo
2026-07-22 00:00CVE-2026-65482
6.4
Medium
Abu HurayraNo
2026-07-10 14:17CVE-2026-15338
7.5
High
Wordfence PRISMYes
2026-06-19 00:00CVE-2026-12276
5.3
Medium
Mike GozdiskowskiYes
2026-01-21 17:31CVE-2026-0920
9.8
Critical
Athiwat Tiprasaharn (Jitlada)Yes
2025-12-15 00:00CVE-2026-24947
5.3
Medium
NumeXYes
2025-09-05 00:00CVE-2025-8360
6.4
Medium
zer0gh0stYes
2025-05-29 22:06CVE-2025-4944
6.4
Medium
Robert DeVoreYes
2025-05-29 18:09CVE-2025-4943
6.4
Medium
WebbernautYes
Showing 1–10 of 23 reports
Plugin Profile
Latestv1.6.2

LA-Studio Element Kit for Elementor

LA-Studio

Author

LA-Studio

5.0(7)
100/100
Last Updated
2026-07-10 (2mo ago)
Active Installs
10,000+
Downloads
236,743
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 7.0.0
Created
2021-03-24 (6y ago)

LA-Studio Kit is an ultimate All in one addons for Elementor Page Builder, it will help you create a perfect website using Elementor. KEY FEATURES Header Footer Builder Theme Builder Archive Page Builder Search Result Page Builder 50+ Free Widgets 35+ Ready Pages 50+ Ready Sections WooCommerce Widgets Cross-Browser Compatible Fully Responsive Expert Support Team Build with Elementor and more … SUPPORT Found issue or new features? Contact our team from here.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C