LA-Studio Element Kit for Elementor <= 1.6.0 - Unauthenticated Open Registration

2026-06-19 00:00
Mike Gozdiskowski

Strategic Overview

Status
Patched in 1.6.1
Affected Version<= 1.6.0
CVSS5.3Medium
CVECVE-2026-12276
View all LA-Studio Element Kit for Elementor vulnerabilities

Vulnerability Overview

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to open registration in all versions up to, and including, 1.6.0. This is due to the plugin not properly check core options for site registration settings. This makes it possible for unauthenticated attackers to register on sites where it should be disabled.

Technical Analysis

REMEDIATION: Update to version 1.6.1, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C

LA-Studio Element Kit for Elementor <= 1.6.0 - Unauthenticated Open Registration (CVE-2026-12276)