SecAlerts
l

la-studio

Security Risk Profile

42
/100
medium

Security Risk Score

Comprehensive risk assessment based on 17 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 14, 2024 to present

17
Total CVEs
4
Critical+High
0
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
6.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
42/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
0
High
4
Medium
13
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
11
2
SSRF
1
3
CSRF
1

Most Affected Products

1. LA-Studio Element Kit for Elementor11
2. LA-Studio LA-Studio Element Kit for Elementor6
3. La-studioweb Element Kit For Elementor Wordpress3
4. La-studioweb La-studio Element Kit For Elementor Wordpress2
5. WordPress LA-Studio Element Kit for Elementor2

Recent Vulnerabilities

See more →
CVE-2026-103082
CVSS 7.2high

WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Server Side Request Forgery (SSRF) vulnerability

Oct 1, 2026🔧 No Patch
CVE-2026-65489
CVSS 5.3medium

WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Broken Access Control vulnerability

Jul 23, 2026🔧 No Patch
CVE-2026-65488
CVSS 7.1high

WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability

Jul 23, 2026🔧 No Patch
CVE-2026-65482
CVSS 6.5medium

WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.3 - Cross Site Scripting (XSS) vulnerability

Jul 23, 2026🔧 No Patch
CVE-2025-8360
CVSS 6.4medium

LA-Studio Element Kit for Elementor <= 1.5.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

Sep 6, 2025🔧 No Patch
CVE-2025-4944
CVSS 6.4EPSS 0%medium

LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Compare and Google Maps Widgets

May 30, 2025🔧 No Patch
CVE-2025-4943
CVSS 6.4EPSS 0%medium

LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter

May 30, 2025
CVE-2025-3106
CVSS 6.4medium

LA-Studio Element Kit for Elementor <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget

Apr 18, 2025🔧 No Patch
CVE-2025-32194
CVSS 6.5EPSS 0%medium

WordPress LA-Studio Element Kit for Elementor plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability

Apr 4, 2025🔧 No Patch
CVE-2023-50884
CVSS 6.5medium

WordPress LA-Studio Element Kit for Elementor plugin <= 1.1.5 - Broken Access Control vulnerability

Dec 9, 2024

Monitor la-studio in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

la-studio Security Vulnerabilities & Risk Score | 17 CVEs | SecAlerts - SecAlerts