Pricing
Case studies
Login
Start trial
LA-Studio Element Kit for Elementor
LA-Studio
Developer
1.6.0
Latest version
10,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
18 patched
3 Mitigation rules
Authenticated (Contributor+) Local File Inclusion vulnerability
<= 1.3.8.1
02/02/2026
Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter vulnerability
<= 1.5.6.3
21/01/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget vulnerability
<= 1.4.9
31/12/2025
Broken Access Control vulnerability
< 1.5.6.3
15/12/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets vulnerability
<= 1.5.5.1
06/09/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Image Compare and Google Maps Widgets vulnerability
<= 1.5.2
30/05/2025
Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter vulnerability
<= 1.5.2
30/05/2025
Cross Site Scripting (XSS) vulnerability
<= 1.5.1
04/04/2025
Authenticated (Contributor+) Post Disclosure vulnerability
<= 1.4.4
03/12/2024
Authenticated (Contributor+) Local File Inclusion vulnerability
<= 1.4.2
22/11/2024
Cross Site Scripting (XSS) vulnerability
<= 1.3.9.3
30/09/2024
Cross Site Scripting (XSS) vulnerability
<= 1.3.9.2
09/08/2024
Local File Inclusion vulnerability
<= 1.3.8.1
02/07/2024
Broken Access Control vulnerability
<= 1.3.6
06/06/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.3.7.6
23/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via LaStudioKit Post Author Widget vulnerability
<= 1.3.7.5
03/05/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 1.3.7.4
14/03/2024
Broken Access Control vulnerability
<= 1.1.5
26/12/2023