Junglewise Threat Intelligence

CVE-2026-65489: LA-Studio Element Kit for Elementor broken access control

CVE-2026-65489 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Technologies: LA-Studio Element Kit for Elementor. Vendors: LA-Studio.

Executive brief

The LA-Studio Element Kit for Elementor, a WordPress plugin used to add custom design elements to websites, contains a security flaw that allows unauthorized users to bypass access controls. An attacker could exploit this to perform actions or access information that should be restricted to site administrators. While the impact is currently rated as medium, such vulnerabilities are often targeted in automated attacks against WordPress sites.

Technical details

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in versions up to and including 1.6.2. This vulnerability allows an unauthenticated remote attacker to execute functions or access data that should be restricted to higher-privileged users. The attack can be carried out over the network without any user interaction. As of the advisory date, no official patch has been released, and users are advised to monitor for updates from the developer.

Affected products

  • LA-Studio LA-Studio Element Kit for Elementor <= 1.6.2

Timeline

  • 2026-02-04: other: Vulnerability reported by researcher
  • 2026-07-22: advisory: Patchstack published advisory
  • 2026-07-23: disclosed: CVE published to NVD

References

Related threats