Input validation vulnerability in LA-Studio Element Kit for Elementor 1.3.7.4

The LA-Studio Element Kit for Elementor plugin used in WordPress has a security flaw that allows for Stored Cross-Site Scripting. This is due to a lack of proper filtering and escaping of user input, specifically in the LinkWrapper attribute used in multiple widgets. This vulnerability exists in all versions up to 1.3.7.4, and can be exploited by attackers with contributor-level or higher permissions. They can inject harmful web scripts into pages, which will run whenever a user opens the page.

Detected in:

LA-Studio Element Kit for Elementor fixed vulnerable versions: >= * <= 1.3.7.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.