SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-12276

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The LA-Studio Element Kit for Elementor plugin for WordPress prior to version 1.6.1 is vulnerable as it allows unauthenticated attackers to create new user accounts via its AJAX actions, regardless of the site's user registration settings. This can lead to unauthorized access and potential exploitation of user accounts. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-12276
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%
WordPress

Original NVD Description

The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating an account through one of its unauthenticated AJAX actions, allowing unauthenticated attackers to register new accounts even when registration has been disabled site-wide.