Impact
The LA‑Studio Element Kit for Elementor plugin contains a Local File Inclusion flaw in all versions up to 1.6.1. The get_type_template function normalizes a user‑supplied widget setting only by adjusting directory separators and appending a file extension; it does not resolve or reject path‑traversal sequences. As a result, an authenticated attacker with contributor or higher privileges can craft a traversal payload in the progress_type widget setting that points to an arbitrary .php file on the server. The plugin will then include and execute that file, allowing, bypass role‑based access controls, or exfiltrate sensitive data stored in the application environment.
Affected Systems
WordPress sites that have the LA‑Studio Element Kit for Elementor plugin installed at version 1.6.1 or earlier are affected. Any user who possesses contributor‑level or higher permissions and can edit widget settings for the progress bar is able to trigger the flaw.
Risk and Exploitability
With a CVSS score of 7.5, this vulnerability is classified as high. The EPSS score is under 1 %, indicating a very low public exploitation probability. Although it is not listed in the CISA KEV catalog, the potential impact—remote code execution, access control bypass, and data theft—demands immediate remediation.
OpenCVE Enrichment