Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-0920 — Explanation and payload of the recent vulnerability in the LA-Studio Element WordPress plugin. | Kitploit
Tools/GitHubGitHub/john-doe-code-a11/cve-2026-0920
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPayload Development
GitHubjohn-doe-code-a11/cve-2026-0920

CVE-2026-0920

Explanation and payload of the recent vulnerability in the LA-Studio Element WordPress plugin.

View Repository
7108 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Exploit Research: CVE-2026-0920 - LA-Studio Element Kit Backdoor

Technical analysis and Proof of Concept (PoC) for the critical backdoor discovered in LA-Studio Element Kit for Elementor (versions ≤ 1.5.6.3). This vulnerability allows unauthenticated administrative account creation.

Vulnerability Overview

A backdoor was intentionally inserted into the ajax_register_handle function by a former employee, allowing the use of a hidden parameter to elevate user privileges during registration.

Vulnerability Type: Improper Authorization / Intentional Backdoor.

Target Function: ajax_register_handle.

Backdoor Parameter: lakit_bkrole.

Impact: Full Site Takeover.

Proof of Concept (PoC)

  1. Analysis of the Vector The vulnerability is triggered via a POST request to /wp-admin/admin-ajax.php. The attacker must send a JSON-encoded payload within the actions parameter.

Key Requirements:

A valid WordPress AJAX nonce (_nonce).

The lakit_bkrole parameter set to administrator.

  1. Exploitation Steps Identify Target: Locate a page using the kit's registration features. Poc1
Poc2

Capture Nonce: Intercept a legitimate registration request or inspect the page source to find the _nonce for the lakit_ajax action. Poc3 Poc4

Run Exploit: Execute the Python script providing the target URL, the captured nonce, and desired credentials. Poc5

  1. Automated Exploit Execution (CVE-2026-0920.py) The script automates the creation of the malicious JSON structure.

Example Command:

python CVE-2026-0920.py -u https://spoilhouses.s2-tastewp.com -n b935edabf2 -ua "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" --user "john_admin" --passw "ComplexPass123"

Terminal Output:

Plaintext SUCCESS: john_admin created.

  1. Verification Upon execution, the attacker gains full access.

Outcome: The new user john_admin is visible in the WordPress Users panel with the Administrator profile. image

Payload Detail (Burp Suite View)

The intercepted request reveals how the backdoor is triggered:

Endpoint: /wp-admin/admin-ajax.php.

Action: lakit_ajax.

Malicious Data: The JSON string inside the actions parameter explicitly includes "lakit_bkrole":"administrator", which the plugin processes to grant full site privileges.

🛠️ Mitigation Update: Immediately upgrade to v1.6.0.

Audit: Review the wp_users table for any unauthorized administrators created recently, such as john_admin.

Cleanup: Remove any suspicious accounts found and rotate all legitimate administrator passwords.

Download Tool