SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65489

MEDIUM · CVSS 5.3 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The LA-Studio Element Kit for Elementor versions up to 1.6.2 are vulnerable to unauthenticated broken access control, allowing attackers to potentially access restricted resources without proper authentication. This vulnerability could lead to unauthorized data exposure or manipulation, making it critical for web developers and administrators using this plugin to prioritize patching or upgrading to mitigate risks. Organizations relying on this tool should assess their exposure and implement necessary security measures promptly.

CVE
CVE-2026-65489
Severity
MEDIUM
CVSS
5.3
EPSS
0.23%

Original NVD Description

Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.