Extension WordPress
Vulnérabilités LA-Studio Element Kit for Elementor
Cette page rassemble les failles publiées pour LA-Studio Element Kit for Elementor, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de LA-Studio Element Kit for Elementor
19 fiches
LA-Studio Element Kit for Elementor <= 1.6.1 – Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.6.1
1.6.2
10/07/2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 – Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.6.3. This is due to the 'ajax_register_handle' function not restricting what user roles a user can…
*-1.5.6.3
1.6.0
21/01/2026
LA-Studio Element Kit for Elementor < 1.5.6.3 – Missing Authorization
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 1.5.6.3 (exclusive). This makes it possible for unauthenticated attackers to…
[*, 1.5.6.3)
1.5.6.3
15/12/2025
LA-Studio Element Kit for Elementor <= 1.5.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets in all versions up to, and including, 1.5.5.1 due to insufficient input sanitization and output escaping on…
*-1.5.5.1
1.5.5.2
05/09/2025
LA-Studio Element Kit for Elementor <= 1.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Image Compare and Google Maps Widgets
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Compare and Google Maps widgets in all versions up to, and including, 1.5.2 due to insufficient input sanitization and…
*-1.5.2
1.5.3
30/05/2025
LA-Studio Element Kit for Elementor <= 1.5.2 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-lakit-element-link’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it…
*-1.5.2
1.5.3
29/05/2025
LA-Studio Element Kit for Elementor <= 1.4.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping…
*-1.4.9
1.5.0
17/04/2025
LA-Studio Element Kit for Elementor <= 1.5.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.5.1
1.5.2
04/04/2025
LA-Studio Element Kit for Elementor <= 1.4.4 – Authenticated (Contributor+) Post Disclosure
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.4 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes…
*-1.4.4
1.4.5
03/12/2024
LA-Studio Element Kit for Elementor <= 1.4.2 – Authenticated (Contributor+) Local File Inclusion
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the _load_template function. This makes it possible for authenticated attackers, with Contributor-level access and…
*-1.4.2
1.4.3
22/11/2024
LA-Studio Element Kit for Elementor <= 1.3.9.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-1.3.9.3
1.3.9.7
30/09/2024
LA-Studio Element Kit for Elementor <= 1.3.9.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.9.2 due to insufficient input sanitization and output escaping on title tags found in blocks. This makes…
*-1.3.9.2
1.3.9.3
09/08/2024
LA-Studio Element Kit for Elementor <= 1.3.8.1 – Authenticated (Contributor+) Local File Inclusion via 'progress_type'
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'progress_type' attribute of the Progress Bar widget. This makes it possible for authenticated…
*-1.3.8.1
1.3.9
02/07/2024
LA-Studio Element Kit for Elementor <= 1.3.8.1 – Authenticated (Contributor+) Local File Inclusion
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'map_style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and…
*-1.3.8.1
1.3.9
01/07/2024
LA-Studio Element Kit for Elementor <= 1.3.6 – Missing Authorization
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated attackers…
*-1.3.6
1.3.7.4
06/06/2024
LA-Studio Element Kit for Elementor <= 1.3.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.7.6 due to insufficient input sanitization and output escaping. This makes it…
*-1.3.7.6
1.3.8
22/05/2024
LA-Studio Element Kit for Elementor <= 1.3.7.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via LaStudioKit Post Author Widget
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's LaStudioKit Post Author widget in all versions up to, and including, 1.3.7.5 due to insufficient input sanitization and output escaping…
*-1.3.7.5
1.3.7.6
01/05/2024
LA-Studio Element Kit for Elementor <= 1.3.7.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWrapper attribute found in several widgets in all versions up to, and including, 1.3.7.4 due to insufficient input sanitization and output…
*-1.3.7.4
1.3.7.5
14/03/2024
LA-Studio Element Kit for Elementor <= 1.1.5 – Missing Authorization
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a REST-API endpoint in versions up to, and including, 1.1.5. This makes it possible for…
*-1.1.5
1.1.6
26/12/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.