Sabotage & Exploited in the Wild: Critical Backdoor Found in LA-Studio Element Kit
ID: e44ece4a-aea5-54ff-9a5c-513cfdb1d10d
STIX ID: report--e44ece4a-aea5-54ff-9a5c-513cfdb1d10d
Feed Name: securityonline.info
Threat Score
A critical backdoor (CVE-2026-0920, CVSS 9.8) was found in the LA-Studio Element Kit for Elementor, present on ~20,000 sites, which allowed unauthenticated creation of administrator accounts via an obfuscated parameter (lakit_bkrole); the vendor stated a former employee planted the malicious code, Wordfence observed active attacks (216 blocked in 24 hours), and a patch (v1.6.0) was released the day after disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
