Description
Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Published: 2026-07-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a contributor Cross Site Scripting (XSS) flaw in the LA‑Studio Element Kit for Elementor plugin version 1.6.2 and earlier. An attacker can inject arbitrary script into content managed by the plugin, resulting in browser‑based script execution when affected pages are viewed. This flaw is classified as CWE‑79.

Affected Systems

The issue affects all WordPress sites that have installed the LA‑Studio Element Kit for Elementor plugin version 1.6.2 or earlier. The vendor is LA‑Studio and the plugin is commonly integrated into WordPress sites via the Elementor page builder.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% shows a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must be able to submit or edit content through the plugin’s editor to deliver malicious code, implying an authenticated or local access attack vector rather than a purely remote one.

Generated by OpenCVE AI on August 3, 2026 at 22:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the LA‑Studio Element Kit for Elementor plugin to a version newer than 1.6.2 if an update is available.
  • If upgrading is not immediately possible, disable or remove the plugin to eliminate the attack surface.
  • Enable WordPress’s built-in content sanitization filters or configure the plugin to restrict allowed HTML tags for any content created with the plugin.

Generated by OpenCVE AI on August 3, 2026 at 22:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared La-studioweb
La-studioweb element Kit For Elementor
Wordpress
Wordpress wordpress
Vendors & Products La-studioweb
La-studioweb element Kit For Elementor
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Title WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

La-studioweb Element Kit For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:28:48.738Z

Reserved: 2026-07-22T08:53:30.834Z

Link: CVE-2026-65482

cve-icon Vulnrichment

Updated: 2026-07-23T13:28:43.939Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:41.220

Modified: 2026-07-23T14:17:51.903

Link: CVE-2026-65482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')