Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityinternet-facing-service-vulnerabilityextension-plugin-hijackwidely-deployed-product-advisory

Backdoored LA-Studio Element Kit WordPress Plugin Enables Unauthenticated Admin Account Creation

Updated 3mo agoFirst seen Jan 23, 20263 sources

A critical backdoor was identified in the LA-Studio Element Kit for Elementor WordPress plugin (active on 20,000+ sites), enabling unauthenticated attackers to create administrator accounts and take full control of affected websites. The issue is tracked as CVE-2026-0920 with a CVSS 9.8 rating, and exploitation has been reported in the wild. The malicious logic was embedded in the plugin’s registration flow, allowing attackers to elevate privileges during account creation and then perform typical admin-level actions such as uploading malicious files, injecting spam, or redirecting visitors.

Technical reporting attributes the backdoor to sabotage: the vendor stated the malicious code was planted by a former employee, with changes occurring around the time their employment ended. The vulnerable path is the ajax_register_handle() function, where attackers can supply a specific registration parameter, lakit_bkrole, to obtain administrator capability; the code was described as obfuscated to evade detection. CVE documentation characterizes the weakness as improper restriction of user role assignment during registration (mapped to CWE-269) and points to the affected versions up to and including 1.5.6.3, along with upstream code references and the associated Wordfence advisory.

Share:
Backdoored LA-Studio Element Kit WordPress Plugin Enables Unauthenticated Admin Account Creation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Feb 12, 20264mo ago

Wordfence schedules Free user protection rollout

Wordfence said protection for free-tier users would become available on February 12, 2026, after Premium users had already received coverage. This marked the broader rollout of defensive coverage for sites still running vulnerable plugin versions.

Jan 23, 20265mo ago

Wordfence reports active exploitation in the wild

Wordfence said attackers were actively exploiting the backdoor and that it blocked 216 attack attempts in a 24-hour period. Public reporting also highlighted the vendor's claim that the issue stemmed from insider sabotage by a former employee.

Jan 22, 20265mo ago

CVE-2026-0920 is received and documented

The vulnerability was assigned CVE-2026-0920 and the CVE record notes it was received by security@wordfence.com on January 22, 2026. The entry described the flaw as unauthenticated privilege escalation through improper role restriction in ajax_register_handle().

Jan 14, 20265mo ago

LA-Studio releases version 1.6.0 to remove the backdoor

LA-Studio issued a patch in plugin version 1.6.0 to fix the vulnerability and remove the malicious code. Users were urged to update immediately because affected versions were installed on more than 20,000 WordPress sites.

Jan 13, 20265mo ago

Wordfence notifies LA-Studio and deploys Premium protection

Wordfence notified the vendor about the backdoor vulnerability and began protecting Premium users against exploitation. The issue was already being treated as critical because it enabled full site takeover through unauthenticated admin creation.

Jan 12, 20265mo ago

Researcher reports admin-creation backdoor to Wordfence

Researchers discovered the vulnerability in LA-Studio Element Kit for Elementor and reported it through the Wordfence Bug Bounty Program. The flaw affected versions up to and including 1.5.6.3 and allowed unauthenticated administrator account creation via the lakit_bkrole parameter.

Dec 25, 20256mo ago

Former employee allegedly plants backdoor in plugin code

LA-Studio said a former employee intentionally introduced obfuscated backdoor logic into the Element Kit for Elementor plugin shortly before leaving in late December 2025. The code allowed a hidden registration parameter to assign administrator privileges to a newly created user.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Affected products
2 linked
WordpressWordfence
Organizations
5 linked
WordfenceAsustorEatonTrump Media & Technology GroupLA-Studio
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.