CVE-2026-65489: WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LA-Studio Element Kit for Elementorto a version that resolves this vulnerability.Fixed in 1.6.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65489?
The severity of CVE-2026-65489 is rated as medium with a score of 5.3.
What type of vulnerability is CVE-2026-65489?
CVE-2026-65489 is categorized as an Unauthenticated Broken Access Control vulnerability.
How do I fix CVE-2026-65489?
To fix CVE-2026-65489, update the LA-Studio Element Kit for Elementor plugin to version 1.6.3 or later.
What impact does CVE-2026-65489 have on affected systems?
CVE-2026-65489 can allow unauthorized users to access restricted areas of the WordPress site.
Which versions of the plugin are affected by CVE-2026-65489?
CVE-2026-65489 affects versions of the LA-Studio Element Kit for Elementor plugin that are 1.6.2 and below.