CVE-2025-32194: WordPress LA-Studio Element Kit for Elementor plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Stored XSS. This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.4.9.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Stored XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through <= 1.5.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32194?
CVE-2025-32194 is classified as a high severity vulnerability due to its potential for Stored XSS attacks.
How does CVE-2025-32194 affect users of LA-Studio Element Kit for Elementor?
CVE-2025-32194 allows attackers to inject malicious scripts into web pages viewed by users, leading to unauthorized actions or data theft.
How do I fix CVE-2025-32194?
To mitigate CVE-2025-32194, update the LA-Studio Element Kit for Elementor to version 1.5.0 or later.
Which versions of LA-Studio Element Kit for Elementor are vulnerable to CVE-2025-32194?
Versions of LA-Studio Element Kit for Elementor from n/a up to and including 1.4.9 are vulnerable to CVE-2025-32194.
What type of vulnerability is CVE-2025-32194 classified as?
CVE-2025-32194 is classified as a Cross-Site Scripting (XSS) vulnerability.