Impact
Unauthenticated Cross Site Request Forgery in LA‑Studio Element Kit for Elementor through version 1.6.2 lets an attacker submit malicious input that is stored in the WordPress database. The likely impact is that when a page rendering that input is viewed, the embedded script may execute in the victim’s browser, potentially stealing cookies, defacing the site, or launching further phishing attacks. The weakness is identified as CWE‑352, highlighting the lack of origin or token validation for state‑changing requests.
Affected Systems
The vulnerability affects installations of the WordPress plugin LA‑Studio Element Kit for Elementor version 1.6.2 and older. Site administrators who still run the affected plugin are exposed, regardless of user role, because the CSRF vector does not require prior authentication.
Risk and Exploitability
The vulnerability is scored 7.1 on the CVSS scale, indicating a high impact to confidentiality, integrity, and availability at the client side. The EPSS score is below 1 %, suggesting that automated exploitation has not been widely observed. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by crafting a malicious link that forces a victim to load a page that triggers the stored payload; based on the description, this can be done passively by a compromised partner site or as part of a social engineering campaign. The lack of an authentication requirement suggests that the barrier to execution could be minimal for the attacker, but because the exploit is client‑side, defenders can mitigate it with proper content‑security policies and by removing or updating the plugin.
OpenCVE Enrichment