VYPR

LA-Studio Element Kit for Elementor

by WordPress

CVEs (22)

  • CVE-2026-15338HigJul 11, 2026
    risk 0.00cvss 7.5epss 0.01

    The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to…

  • CVE-2026-12276MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.00

    The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating an account through one of its unauthenticated AJAX actions, allowing unauthenticated attackers to register new accounts even when…

Page 2 of 2