Junglewise Threat Intelligence

CVE-2026-15338: choijun LA-Studio Element Kit for Elementor Local File Inclusion in get_type_template

CVE-2026-15338 · Severity: high · CVSS 7.5 · Published 2026-07-11

Executive brief

The LA-Studio Element Kit for Elementor, a WordPress plugin used to enhance website design capabilities, contains a security flaw that allows users with basic contributor-level access to execute unauthorized code. By exploiting this vulnerability, an attacker could potentially gain full control over the website, access sensitive data, or bypass security restrictions. This issue affects all versions of the plugin up to and including 1.6.1.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the LA-Studio Element Kit for Elementor plugin due to insufficient path validation in the get_type_template function. The implementation uses wp_normalize_path, which only normalizes directory separators and fails to resolve or block path traversal sequences (e.g., ../). An authenticated attacker with contributor-level permissions can provide a crafted payload that bypasses extension checks because the application automatically appends the required .php extension. If an attacker can upload a malicious PHP file (e.g., via another feature or vulnerability), they can use this LFI to execute that code in the context of the web server. The vulnerability is present in all versions up to and including 1.6.1.

Affected products

  • choijun LA-Studio Element Kit for Elementor up to, and including, 1.6.1

Timeline

  • 2026-07-11: advisory: NVD publication date

References