Description
Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Published: 2026-07-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Cross Site Request Forgery in LA‑Studio Element Kit for Elementor through version 1.6.2 lets an attacker submit malicious input that is stored in the WordPress database. The likely impact is that when a page rendering that input is viewed, the embedded script may execute in the victim’s browser, potentially stealing cookies, defacing the site, or launching further phishing attacks. The weakness is identified as CWE‑352, highlighting the lack of origin or token validation for state‑changing requests.

Affected Systems

The vulnerability affects installations of the WordPress plugin LA‑Studio Element Kit for Elementor version 1.6.2 and older. Site administrators who still run the affected plugin are exposed, regardless of user role, because the CSRF vector does not require prior authentication.

Risk and Exploitability

The vulnerability is scored 7.1 on the CVSS scale, indicating a high impact to confidentiality, integrity, and availability at the client side. The EPSS score is below 1 %, suggesting that automated exploitation has not been widely observed. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by crafting a malicious link that forces a victim to load a page that triggers the stored payload; based on the description, this can be done passively by a compromised partner site or as part of a social engineering campaign. The lack of an authentication requirement suggests that the barrier to execution could be minimal for the attacker, but because the exploit is client‑side, defenders can mitigate it with proper content‑security policies and by removing or updating the plugin.

Generated by OpenCVE AI on August 3, 2026 at 22:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the LA‑Studio Element Kit for Elementor plugin to the latest released version that addresses the CSRF-to-stored‑XSS flaw
  • If an upgrade is not immediately feasible, disable or delete the affected plugin to prevent stored payload execution and remove any injected content from the database
  • Maintain your WordPress core and all other plugins at their latest secure releases, and regularly scan the site for injected scripts or suspicious content

Generated by OpenCVE AI on August 3, 2026 at 22:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared La-studioweb
La-studioweb element Kit For Elementor
Wordpress
Wordpress wordpress
Vendors & Products La-studioweb
La-studioweb element Kit For Elementor
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Title WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

La-studioweb Element Kit For Elementor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:28:27.843Z

Reserved: 2026-07-22T08:53:35.327Z

Link: CVE-2026-65488

cve-icon Vulnrichment

Updated: 2026-07-23T13:28:24.199Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:41.943

Modified: 2026-07-23T14:17:52.750

Link: CVE-2026-65488

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:00:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)