Description
The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating an account through one of its unauthenticated AJAX actions, allowing unauthenticated attackers to register new accounts even when registration has been disabled site-wide.
Published: 2026-07-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The LA‑Studio Element Kit for Elementor plugin for WordPress allows any visitor to trigger an unauthenticated AJAX action that creates a new WordPress account. The code does not verify whether site‑wide user registration is enabled before processing the request, meaning attackers can register an account even when the global registration setting is disabled.

Affected Systems

WordPress installations that use the LA‑Studio Element Kit for Elementor plugin below version 1.6.1 are affected.

Risk and Exploitability

The vulnerability permits unauthenticated creation of user accounts regardless of site registration settings. The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The CVE is not listed in the CISA KEV catalog, so there is no public evidence of exploitation. The description does not specify which WordPress role is assigned to newly created accounts, leaving the privilege impact uncertain.

Generated by OpenCVE AI on July 28, 2026 at 08:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the LA‑Studio Element Kit for Elementor plugin to version 1.6.1 or newer, which disables the unauthenticated registration endpoint.
  • Disable the WordPress global registration setting (Settings → General → Membership: Anyone can register) to reduce the attack surface, although the plugin bypasses this setting.
  • Review the site’s user list for recent registrations, remove suspicious accounts, or force password changes on those accounts.

Generated by OpenCVE AI on July 28, 2026 at 08:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 25 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 22 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Fri, 17 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 16 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 13 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 13 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-639

Fri, 10 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-639

Fri, 10 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating an account through one of its unauthenticated AJAX actions, allowing unauthenticated attackers to register new accounts even when registration has been disabled site-wide.
Title LA-Studio Element Kit for Elementor < 1.6.1 - Unauthenticated Open Registration
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-10T11:35:01.651Z

Reserved: 2026-06-15T11:20:40.470Z

Link: CVE-2026-12276

cve-icon Vulnrichment

Updated: 2026-07-10T11:34:51.176Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses