Executive brief
LA-Studio Element Kit for Elementor is a WordPress plugin used to add custom widgets and design elements to websites. A security vulnerability allows users with 'Contributor' level access to inject malicious scripts into web pages. If a site administrator or visitor views the affected content, these scripts could lead to unauthorized actions, data theft, or website defacement.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the LA-Studio Element Kit for Elementor plugin for WordPress (versions up to and including 1.6.2). The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with Contributor-level privileges can inject malicious JavaScript into plugin-managed components. This script executes in the context of a victim's browser when they visit the affected page, requiring some user interaction. As of the advisory date, no official patch has been released.
Affected products
- LA-Studio LA-Studio Element Kit for Elementor <= 1.6.2
Timeline
- 2026-01-30: disclosed: Reported by Abu Hurayra via Patchstack
- 2026-07-23: advisory: NVD publication date