PT-2026-57381 · WordPress · La-Studio Element Kit For Elementor

·

CVE-2026-15338

·

Published

2026-07-11

·

Updated

2026-07-11

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LA-Studio Element Kit for Elementor versions prior to 1.6.2
Description The LA-Studio Element Kit for Elementor plugin for WordPress contains a Local File Inclusion flaw. Authenticated users with contributor-level access or higher can exploit the get type template() function to include and execute arbitrary .php files on the server. This occurs because the wp normalize path() function used in get template() only normalizes directory separators and fails to resolve or reject path traversal sequences. Additionally, the extension check is bypassed as the caller appends the required extension to the traversal payload. This issue can lead to the execution of arbitrary PHP code, bypassing of access controls, and unauthorized access to sensitive data.
Recommendations Update the plugin to a version newer than 1.6.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15338

Affected Products

La-Studio Element Kit For Elementor