The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.6.3. This is due to the 'ajax_register_handle' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'lakit_bkrole' parameter during registration and gain administrator access to the site.
https://github.com/katranSefa/CVE-2026-0920
https://github.com/Dx3iZ/CVE-2026-0920
https://github.com/system-bliss/vuln-lab-docker
https://github.com/Harb656/CVEsWorpriss
https://github.com/ridhinva/hermes-vuln-tools
https://github.com/InMyMine7/Mephisto
https://github.com/Nxploited/CVE-2026-0920-
https://github.com/O99099O/By-Poloss..-..CVE-2026-0920
https://plugins.trac.wordpress.org/changeset/3439121/lastudio-element-kit