Impact
The vulnerability is a contributor Cross Site Scripting (XSS) flaw in the LA‑Studio Element Kit for Elementor plugin version 1.6.2 and earlier. An attacker can inject arbitrary script into content managed by the plugin, resulting in browser‑based script execution when affected pages are viewed. This flaw is classified as CWE‑79.
Affected Systems
The issue affects all WordPress sites that have installed the LA‑Studio Element Kit for Elementor plugin version 1.6.2 or earlier. The vendor is LA‑Studio and the plugin is commonly integrated into WordPress sites via the Elementor page builder.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% shows a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must be able to submit or edit content through the plugin’s editor to deliver malicious code, implying an authenticated or local access attack vector rather than a purely remote one.
OpenCVE Enrichment