Cross Site Scripting Vulnerability in LA-Studio Element Kit for Elementor
CVE-2026-65482

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-65482?

A Cross Site Scripting (XSS) vulnerability exists in LA-Studio Element Kit for Elementor versions up to 1.6.2. This flaw allows attackers to inject malicious scripts into web pages viewed by users, which can lead to unauthorized actions on behalf of users and compromise sensitive information. It is crucial for users of this plugin to ensure they are running patched versions to mitigate potential risks associated with this vulnerability.

Affected Version(s)

LA-Studio Element Kit for Elementor <= 1.6.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abu Hurayra | Patchstack Bug Bounty Program
.