La Studioweb develops WordPress plugin extensions for the Elementor page builder, with its vulnerability footprint centered on the Element Kit product line. The exposure reflects the plugin's web-facing context and its role in user-controlled page construction and rendering within WordPress environments. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by La Studioweb over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5349HIGH The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'map_style' parameter. This | Jul 2, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-35725HIGH Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.6. | Jun 10, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-10873HIGH The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the _load_template function. This | Nov 23, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-37479HIGH Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically in the "progress_type" attribute | Jul 2, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-4943MEDIUM The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-lakit-element-link’ parameter in all versions up to, and inc | May 30, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-2249MEDIUM The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWrapper attribute found in several widgets in all versions up | Mar 14, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-10787MEDIUM The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.4 via the 'elementor-template' shortcod | Dec 4, 2024 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by La Studioweb.
Media articles that mention a CVE ID that affects a product developed by La Studioweb — matched by CVE ID, not by vendor name.