CVE-2026-65488
Received Received - Intake

Unauthenticated CSRF in LA-Studio Element Kit for Elementor

Vulnerability report for CVE-2026-65488, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: Patchstack

Description

Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-23
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
la-studio element_kit to 1.6.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Unauthenticated Cross Site Request Forgery (CSRF) in the LA-Studio Element Kit for Elementor plugin versions up to and including 1.6.2. CSRF allows attackers to trick users into executing unwanted actions on a web application where they are authenticated, without their knowledge or consent.

Impact Analysis

This vulnerability could allow attackers to perform unauthorized actions on your website if you are using a vulnerable version of the LA-Studio Element Kit for Elementor. These actions could include modifying content, changing settings, or taking administrative actions without your knowledge.

Mitigation Strategies

Update LA-Studio Element Kit for Elementor to the latest version (1.6.2 or higher) to patch the CSRF vulnerability. If an update is not available, consider disabling the plugin temporarily until a fix is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65488. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart