LA-Studio Element Kit for Elementor <= 1.6.0 - Unauthenticated Open Registration
2026-06-19 00:00
Mike GozdiskowskiStrategic Overview
StatusPatched in 1.6.1
Affected PluginLA-Studio Element Kit for Elementor
Affected Version
<= 1.6.0CVSS5.3Medium
CVE
CVE-2026-12276Vulnerability Overview
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to open registration in all versions up to, and including, 1.6.0. This is due to the plugin not properly check core options for site registration settings. This makes it possible for unauthenticated attackers to register on sites where it should be disabled.
Technical Analysis
REMEDIATION: Update to version 1.6.1, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C