Impact
The LA‑Studio Element Kit for Elementor plugin for WordPress allows any visitor to trigger an unauthenticated AJAX action that creates a new WordPress account. The code does not verify whether site‑wide user registration is enabled before processing the request, meaning attackers can register an account even when the global registration setting is disabled.
Affected Systems
WordPress installations that use the LA‑Studio Element Kit for Elementor plugin below version 1.6.1 are affected.
Risk and Exploitability
The vulnerability permits unauthenticated creation of user accounts regardless of site registration settings. The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The CVE is not listed in the CISA KEV catalog, so there is no public evidence of exploitation. The description does not specify which WordPress role is assigned to newly created accounts, leaving the privilege impact uncertain.
OpenCVE Enrichment