CVE-2026-65482: WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.3 - Cross Site Scripting (XSS) vulnerability
Published Jul 23, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows DOM-Based XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.3.
Affected Software
1 affected component
LA-Studio LA-Studio Element Kit for Elementor<=1.6.3
Event History
Jul 23, 2026
CVE Published
via MITRE·11:18 AM
Data Sourced
via MITRE·11:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65482?
The severity of CVE-2026-65482 is medium with a score of 6.5.
2
What type of vulnerability is CVE-2026-65482?
CVE-2026-65482 is a Cross Site Scripting (XSS) vulnerability.
3
How do I fix CVE-2026-65482?
To fix CVE-2026-65482, update the LA-Studio Element Kit for Elementor plugin to version 1.6.3 or later.
4
What impact does CVE-2026-65482 have on users?
CVE-2026-65482 can lead to the execution of arbitrary JavaScript code in the context of a user, potentially compromising user data.
5
Which versions of the LA-Studio Element Kit for Elementor are affected by CVE-2026-65482?
CVE-2026-65482 affects LA-Studio Element Kit for Elementor plugin versions 1.6.2 and earlier.