20,000 WordPress Sites Compromised by Backdoor Vulnerability Enabling Malicious Admin Access
A critical backdoor vulnerability has been identified in the LA-Studio Element Kit for the Elementor plugin, affecting over 20,000 WordPress installations. This vulnerability, known as CVE-2026-0920, has been assigned a CVSS severity rating of 9.8,…
A critical backdoor vulnerability has been identified in the LA-Studio Element Kit for the Elementor plugin, affecting over 20,000 WordPress installations. This vulnerability, known as CVE-2026-0920, has been assigned a CVSS severity rating of 9.8, categorizing it as critical. It allows unauthenticated attackers to create administrator accounts, leading to potential full site compromise.
The vulnerability arises from improper restrictions on user role assignments during registration. Attackers can exploit the lakit_bkrole parameter to assign themselves administrative privileges. The code was obfuscated, indicating deliberate concealment.
Affected versions range from the initial release up to version 1.5.6.3. Attackers with administrative access can upload malicious files, alter website content, inject spam, or redirect users to phishing sites. The vulnerability does not require authentication, making unpatched installations particularly vulnerable.
The vulnerability was traced back to a former LA-Studio employee who inserted the backdoor code before their departure in December 2025. The vulnerability resides in the ajax_register_handle function within the LA-Studio_Kit_Integration class.
This incident reveals significant gaps in code review, developer monitoring, and employee offboarding processes. Organizations are advised to implement stringent access controls and conduct thorough code audits prior to terminating developer accounts.
A critical backdoor vulnerability has been identified in the LA-Studio Element Kit for the Elementor plugin, affecting over 20,000 WordPress installations.
The vulnerability was reported through the Wordfence Bug Bounty Program on January 12, 2026. Wordfence confirmed the exploit within 24 hours and promptly informed LA-Studio via their Vulnerability Management Portal.
The vendor responded swiftly, acknowledging the report and releasing a patched version 1.6.0 on January 14, 2026.
Wordfence Premium, Care, and Response users received firewall protection on January 13, 2026. Free Wordfence users will receive the same protection on February 12, 2026, providing a 30-day advantage for premium subscribers.
Administrators of WordPress sites using the LA-Studio Element Kit for Elementor should update immediately to version 1.6.0. Due to the critical nature of this vulnerability and its potential for site takeover, prompt patching is essential. Administrators should verify their plugin versions and apply updates without delay.
This incident highlights the evolving threat landscape in WordPress security. Insider threats targeting popular plugins can simultaneously affect numerous sites. Organizations should adopt layered security measures, including code review processes, developer monitoring, access revocation procedures, and regular security audits.
WordPress site owners are encouraged to share this advisory with peers using the affected plugin and implement comprehensive vulnerability monitoring through security plugins or managed security services.
Based on reporting by GBHackers.
