Junglewise Threat Intelligence

CVE-2026-65482: LA-Studio Element Kit for Elementor Contributor XSS

CVE-2026-65482 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Technologies: LA-Studio Element Kit for Elementor. Vendors: LA-Studio.

Executive brief

LA-Studio Element Kit for Elementor is a WordPress plugin used to add custom widgets and design elements to websites. A security vulnerability allows users with 'Contributor' level access to inject malicious scripts into web pages. If a site administrator or visitor views the affected content, these scripts could lead to unauthorized actions, data theft, or website defacement.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the LA-Studio Element Kit for Elementor plugin for WordPress (versions up to and including 1.6.2). The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with Contributor-level privileges can inject malicious JavaScript into plugin-managed components. This script executes in the context of a victim's browser when they visit the affected page, requiring some user interaction. As of the advisory date, no official patch has been released.

Affected products

  • LA-Studio LA-Studio Element Kit for Elementor <= 1.6.2

Timeline

  • 2026-01-30: disclosed: Reported by Abu Hurayra via Patchstack
  • 2026-07-23: advisory: NVD publication date

References

Related threats