A severe security flaw has been identified in the LA-Studio Element Kit plugin for Elementor that puts over 20,000 WordPress sites at immediate risk. Assigned CVE-2026-0920 and rated 9.8 on the CVSS scale, the vulnerability allows attackers to register accounts without authentication and escalate privileges to administrator level. The issue stems from improper validation of user roles during registration, where a hidden parameter can be abused to grant full administrative access. The affected versions include all releases from the plugin’s initial launch through version 1.5.6.3, and the absence of authentication requirements makes exploitation trivial for attackers. Further investigation revealed that the backdoor was not accidental but intentionally embedded by a former LA-Studio employee prior to their departure in late December 2025. The malicious logic, found in the ajax_register_handle function of the LA-Studio_Kit_Integration class, was obfuscated to evade detection. This incident highlights the real-world risk posed by insider threats and exposes weaknesses in development oversight, code review enforcement, and employee offboarding practices. The flaw was responsibly disclosed via the Wordfence Bug Bounty Program on January 12, 2026, validated within a day, and promptly communicated to the vendor. LA-Studio responded quickly by releasing a fixed version, 1.6.0, on January 14, 2026. Firewall protection was rolled out to Wordfence Premium, Care, and Response users on January 13, with free users scheduled to receive coverage after a 30-day delay. All site owners running the affected plugin are strongly advised to update immediately, as attackers with administrative access can fully compromise websites by deploying malicious code, altering content, or redirecting visitors to fraudulent destinations. This case serves as a reminder that popular WordPress plugins remain high-value targets and that continuous security monitoring, strict access controls, and regular audits are essential to reducing systemic risk.
Okta has issued a warning about a new wave of highly sophisticated voice-based social engineering (vishing) attacks using custom phishing kits designed to steal Single Sign-On (SSO...
A critical security vulnerability has been disclosed in the GNU InetUtils telnet daemon (telnetd) that allows remote attackers to gain unauthorized root access to affected systems....
Oracle has released its January 2026 Critical Patch Update (CPU), delivering 337 security patches that address around 230 unique CVEs across more than 30 Oracle product families. T...