Junglewise Threat Intelligence

CVE-2026-65488: LA-Studio Element Kit for Elementor CSRF to Stored XSS

CVE-2026-65488 · Severity: high · CVSS 7.1 · Published 2026-07-23

Technologies: LA-Studio Element Kit for Elementor. Vendors: LA-Studio.

Executive brief

LA-Studio Element Kit for Elementor is a WordPress plugin used to add custom widgets and features to the Elementor page builder. A security flaw allows an attacker to trick a site administrator into performing unintended actions, such as injecting malicious scripts into the website. This could lead to the unauthorized modification of site content or the compromise of visitor data.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the LA-Studio Element Kit for Elementor plugin for WordPress (versions <= 1.6.2). The flaw stems from a lack of proper nonce validation, allowing an unauthenticated attacker to craft a malicious request that, if executed by a logged-in administrator, can lead to Stored Cross-Site Scripting (XSS). The attack requires the victim to interact with a malicious link or page. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session, potentially leading to site takeover. As of the advisory date, no official patch has been confirmed.

Affected products

  • LA-Studio LA-Studio Element Kit for Elementor <= 1.6.2

Timeline

  • 2026-02-04: disclosed: Reported by Steven Julian
  • 2026-07-22: advisory: Patchstack published advisory
  • 2026-07-23: advisory: NVD published CVE-2026-65488

References

Related threats