CVE-2025-4943: LA-Studio Element Kit for Elementor <= 1.5.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via data-lakit-element-link Parameter
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-lakit-element-link’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4943?
CVE-2025-4943 is a high severity vulnerability due to its potential for Stored Cross-Site Scripting, making it critical to address.
How do I fix CVE-2025-4943?
To fix CVE-2025-4943, update the LA-Studio Element Kit for Elementor plugin to version 1.5.3 or later.
Who is affected by CVE-2025-4943?
Any WordPress site using LA-Studio Element Kit for Elementor version 1.5.2 or earlier is affected by CVE-2025-4943.
What causes CVE-2025-4943?
CVE-2025-4943 is caused by insufficient input sanitization and output escaping in the ‘data-lakit-element-link’ parameter.
What can attackers achieve through CVE-2025-4943?
Attackers can exploit CVE-2025-4943 to execute malicious scripts in the context of a user's browser, leading to potential data theft or session hijacking.