logo

20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation

ID: 46d5d443-df06-5254-aa3f-0c3a73ba215d

STIX ID: report--46d5d443-df06-5254-aa3f-0c3a73ba215d

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-01-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A critical backdoor (CVE-2026-0920, CVSS 9.8) was found in the LA-Studio Element Kit for Elementor plugin that allowed attackers to create administrative accounts without authentication by supplying a hidden lakit_bkrole parameter; the issue affected versions ≤1.5.6.3 across 20,000+ active sites, was discovered on January 12, 2026, and patched in version 1.6.0 on January 14, 2026. Wordfence analysis found the backdoor was deliberately obfuscated and likely introduced by a departing employee, and Wordfence provided protections while the vendor released the patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.