CVE-2026-65488: WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Stored XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress LA-Studio Element Kit for Elementorto a version that resolves this vulnerability.Fixed in 1.6.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65488?
The severity of CVE-2026-65488 is rated high with a score of 7.1.
How do I fix CVE-2026-65488?
To fix CVE-2026-65488, update the LA-Studio Element Kit for Elementor plugin to version 1.6.3 or later.
What type of vulnerability is CVE-2026-65488?
CVE-2026-65488 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to stored XSS.
Who is affected by CVE-2026-65488?
Users of the LA-Studio Element Kit for Elementor plugin version 1.6.2 or older are affected by CVE-2026-65488.
Can CVE-2026-65488 be exploited remotely?
Yes, CVE-2026-65488 can be exploited remotely due to its unauthenticated nature.