Extension WordPress

Vulnérabilités LA-Studio Element Kit for Elementor

Cette page rassemble les failles publiées pour LA-Studio Element Kit for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.

19Vulnérabilités
1Critiques
19Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de LA-Studio Element Kit for Elementor

19 fiches

CVE-2026-15338 Élevée · 7,5
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.6.1 – Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-1.6.1

Correctif

1.6.2

Publication

10/07/2026

CVE-2026-0920 Critique · 9,8
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.5.6.3 – Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.6.3. This is due to the 'ajax_register_handle' function not restricting what user roles a user can…

Versions affectées

*-1.5.6.3

Correctif

1.6.0

Publication

21/01/2026

CVE-2025-8360 Moyenne · 6,4
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.5.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets in all versions up to, and including, 1.5.5.1 due to insufficient input sanitization and output escaping on…

Versions affectées

*-1.5.5.1

Correctif

1.5.5.2

Publication

05/09/2025

CVE-2025-4944 Moyenne · 6,4
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Compare and Google Maps Widgets

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Compare and Google Maps widgets in all versions up to, and including, 1.5.2 due to insufficient input sanitization and…

Versions affectées

*-1.5.2

Correctif

1.5.3

Publication

30/05/2025

CVE-2025-4943 Moyenne · 6,4
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.5.2 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-lakit-element-link’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.5.2

Correctif

1.5.3

Publication

29/05/2025

CVE-2025-3106 Moyenne · 6,4
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.4.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping…

Versions affectées

*-1.4.9

Correctif

1.5.0

Publication

17/04/2025

CVE-2025-32194 Moyenne · 6,4
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.5.1

Correctif

1.5.2

Publication

04/04/2025

CVE-2024-10787 Moyenne · 4,3
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.4.4 – Authenticated (Contributor+) Post Disclosure

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.4 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes…

Versions affectées

*-1.4.4

Correctif

1.4.5

Publication

03/12/2024

CVE-2024-10873 Élevée · 8,8
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.4.2 – Authenticated (Contributor+) Local File Inclusion

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the _load_template function. This makes it possible for authenticated attackers, with Contributor-level access and…

Versions affectées

*-1.4.2

Correctif

1.4.3

Publication

22/11/2024

CVE-2024-47628 Moyenne · 6,4
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.3.9.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-1.3.9.3

Correctif

1.3.9.7

Publication

30/09/2024

CVE-2024-43210 Moyenne · 6,4
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.3.9.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.9.2 due to insufficient input sanitization and output escaping on title tags found in blocks. This makes…

Versions affectées

*-1.3.9.2

Correctif

1.3.9.3

Publication

09/08/2024

CVE-2024-37479 Moyenne · 5,4
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.3.8.1 – Authenticated (Contributor+) Local File Inclusion via 'progress_type'

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'progress_type' attribute of the Progress Bar widget. This makes it possible for authenticated…

Versions affectées

*-1.3.8.1

Correctif

1.3.9

Publication

02/07/2024

CVE-2024-5349 Élevée · 8,8
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.3.8.1 – Authenticated (Contributor+) Local File Inclusion

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'map_style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and…

Versions affectées

*-1.3.8.1

Correctif

1.3.9

Publication

01/07/2024

CVE-2024-4431 Moyenne · 6,4
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.3.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.7.6 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-1.3.7.6

Correctif

1.3.8

Publication

22/05/2024

CVE-2024-3005 Moyenne · 6,4
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.3.7.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via LaStudioKit Post Author Widget

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's LaStudioKit Post Author widget in all versions up to, and including, 1.3.7.5 due to insufficient input sanitization and output escaping…

Versions affectées

*-1.3.7.5

Correctif

1.3.7.6

Publication

01/05/2024

CVE-2024-2249 Moyenne · 6,4
LA-Studio Element Kit for Elementor

LA-Studio Element Kit for Elementor <= 1.3.7.4 – Authenticated (Contributor+) Stored Cross-Site Scripting

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWrapper attribute found in several widgets in all versions up to, and including, 1.3.7.4 due to insufficient input sanitization and output…

Versions affectées

*-1.3.7.4

Correctif

1.3.7.5

Publication

14/03/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités