Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

20,000 WordPress Sites Compromised by Backdoor Vulnerability Enabling Malicious Admin Access

A critical backdoor vulnerability has been identified in the LA-Studio Element Kit for the Elementor plugin, affecting over 20,000 WordPress installations. This vulnerability, known as CVE-2026-0920, has been assigned a CVSS severity rating of 9.8,…

A critical backdoor vulnerability has been identified in the LA-Studio Element Kit for the Elementor plugin, affecting over 20,000 WordPress installations. This vulnerability, known as CVE-2026-0920, has been assigned a CVSS severity rating of 9.8, categorizing it as critical. It allows unauthenticated attackers to create administrator accounts, leading to potential full site compromise.

The vulnerability arises from improper restrictions on user role assignments during registration. Attackers can exploit the lakit_bkrole parameter to assign themselves administrative privileges. The code was obfuscated, indicating deliberate concealment.

Affected versions range from the initial release up to version 1.5.6.3. Attackers with administrative access can upload malicious files, alter website content, inject spam, or redirect users to phishing sites. The vulnerability does not require authentication, making unpatched installations particularly vulnerable.

The vulnerability was traced back to a former LA-Studio employee who inserted the backdoor code before their departure in December 2025. The vulnerability resides in the ajax_register_handle function within the LA-Studio_Kit_Integration class.

This incident reveals significant gaps in code review, developer monitoring, and employee offboarding processes. Organizations are advised to implement stringent access controls and conduct thorough code audits prior to terminating developer accounts.

A critical backdoor vulnerability has been identified in the LA-Studio Element Kit for the Elementor plugin, affecting over 20,000 WordPress installations.
Madison Drake · Thehackingpost

The vulnerability was reported through the Wordfence Bug Bounty Program on January 12, 2026. Wordfence confirmed the exploit within 24 hours and promptly informed LA-Studio via their Vulnerability Management Portal.

The vendor responded swiftly, acknowledging the report and releasing a patched version 1.6.0 on January 14, 2026.

Wordfence Premium, Care, and Response users received firewall protection on January 13, 2026. Free Wordfence users will receive the same protection on February 12, 2026, providing a 30-day advantage for premium subscribers.

Administrators of WordPress sites using the LA-Studio Element Kit for Elementor should update immediately to version 1.6.0. Due to the critical nature of this vulnerability and its potential for site takeover, prompt patching is essential. Administrators should verify their plugin versions and apply updates without delay.

Advertisement

This incident highlights the evolving threat landscape in WordPress security. Insider threats targeting popular plugins can simultaneously affect numerous sites. Organizations should adopt layered security measures, including code review processes, developer monitoring, access revocation procedures, and regular security audits.

WordPress site owners are encouraged to share this advisory with peers using the affected plugin and implement comprehensive vulnerability monitoring through security plugins or managed security services.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories