Impact
The LA‑Studio Element Kit for Elementor plug‑in for WordPress contains an unauthenticated AJAX endpoint that creates a new user account without verifying whether site‑wide registration is enabled. This flaw allows anyone with internet access to register an account on the site regardless of the WordPress "Anyone can register" setting. The vulnerability is an access control error that can provide attackers with a foothold for further exploitation if the new accounts receive privileged roles.
Affected Systems
WordPress sites that install the LA‑Studio Element Kit for Elementor plug‑in prior to version 1.6.1 are affected.
Risk and Exploitability
An attacker can trigger the problematic AJAX request as an unauthenticated visitor, creating a new WordPress account without credentials. The CVSS score of 5.3 indicates moderate severity, while an EPSS score of less than 1% suggests exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack path is straightforward – any user who finds the plug‑in can register accounts that might be used for later privilege escalation if not monitored.
OpenCVE Enrichment