WordPress security by component
LA-Studio Element Kit for Elementor
Plugin description
LA-Studio Element Kit for Elementor is a WordPress component with 17 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
lastudio-element-kitLatest vulnerability
CVE-2026-65489: LA-Studio Element Kit for Elementor: A security weakness
LA-Studio Element Kit for Elementor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.6.2.
| Safe version |
|
||
|---|---|---|---|
| Jul 23, 2026 |
CVE-2026-65489
LA-Studio Element Kit for Elementor: A security weakness
LA-Studio Element Kit for Elementor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.6.2.
|
> 1.6.2 |
CVE5.3
NVDPending
|
| Jul 23, 2026 |
CVE-2026-65488
LA-Studio Element Kit for Elementor: Cross-site request forgery
LA-Studio Element Kit for Elementor is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 1.6.2.
|
> 1.6.2 |
CVE7.1
NVDPending
|
| Jul 23, 2026 |
CVE-2026-65482
LA-Studio Element Kit for Elementor: Cross-site scripting
LA-Studio Element Kit for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.6.2.
|
> 1.6.2 |
CVE6.5
NVDPending
|
| Jul 11, 2026 |
CVE-2026-15338
LA-Studio Element Kit for Elementor: Filesystem traversal
LA-Studio Element Kit for Elementor is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 1.6.1.
|
> 1.6.1 |
CVE7.5
NVDPending
|
| Feb 03, 2026 |
CVE-2026-24947
LA-Studio Element Kit for Elementor: A security weakness
LA-Studio Element Kit for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jan 22, 2026 |
CVE-2026-0920
LA-Studio Element Kit for Elementor: A security weakness
LA-Studio Element Kit for Elementor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVDPending
|
| May 30, 2025 |
CVE-2025-4944
LA-Studio Element Kit for Elementor: Cross-site scripting
LA-Studio Element Kit for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 30, 2025 |
CVE-2025-4943
LA-Studio Element Kit for Elementor: Cross-site scripting
LA-Studio Element Kit for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 18, 2025 |
CVE-2025-3106
LA-Studio Element Kit for Elementor: Cross-site scripting
LA-Studio Element Kit for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 04, 2025 |
CVE-2025-32194
LA-Studio Element Kit for Elementor: Cross-site scripting
LA-Studio Element Kit for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 09, 2024 |
CVE-2023-50884
LA-Studio Element Kit for Elementor: A security weakness
LA-Studio Element Kit for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Nov 23, 2024 |
CVE-2024-10873
LA-Studio Element Kit for Elementor: Filesystem traversal
LA-Studio Element Kit for Elementor is affected by filesystem traversal. Exploitation requires at least contributor-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Oct 05, 2024 |
CVE-2024-47628
LA-Studio Element Kit for Elementor: Cross-site scripting
LA-Studio Element Kit for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 12, 2024 |
CVE-2024-43210
LA-Studio Element Kit for Elementor: Cross-site scripting
LA-Studio Element Kit for Elementor is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jul 02, 2024 |
CVE-2024-37479
LA-Studio Element Kit for Elementor: Filesystem traversal
LA-Studio Element Kit for Elementor is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| Jun 10, 2024 |
CVE-2024-35725
LA-Studio Element Kit for Elementor: A security weakness
LA-Studio Element Kit for Elementor is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| May 23, 2024 |
CVE-2024-4431
LA-Studio Element Kit for Elementor: Cross-site scripting
LA-Studio Element Kit for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|