
Explanation and payload of the recent vulnerability in the LA-Studio Element WordPress plugin.
Technical analysis and Proof of Concept (PoC) for the critical backdoor discovered in LA-Studio Element Kit for Elementor (versions ≤ 1.5.6.3). This vulnerability allows unauthenticated administrative account creation.
A backdoor was intentionally inserted into the ajax_register_handle function by a former employee, allowing the use of a hidden parameter to elevate user privileges during registration.
Vulnerability Type: Improper Authorization / Intentional Backdoor.
Target Function: ajax_register_handle.
Backdoor Parameter: lakit_bkrole.
Impact: Full Site Takeover.
Key Requirements:
A valid WordPress AJAX nonce (_nonce).
The lakit_bkrole parameter set to administrator.
Capture Nonce: Intercept a legitimate registration request or inspect the page source to find the _nonce for the lakit_ajax action.

Run Exploit: Execute the Python script providing the target URL, the captured nonce, and desired credentials.

Example Command:
python CVE-2026-0920.py -u https://spoilhouses.s2-tastewp.com -n b935edabf2 -ua "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" --user "john_admin" --passw "ComplexPass123"
Terminal Output:
Plaintext SUCCESS: john_admin created.
Outcome: The new user john_admin is visible in the WordPress Users panel with the Administrator profile.

The intercepted request reveals how the backdoor is triggered:
Endpoint: /wp-admin/admin-ajax.php.
Action: lakit_ajax.
Malicious Data: The JSON string inside the actions parameter explicitly includes "lakit_bkrole":"administrator", which the plugin processes to grant full site privileges.
🛠️ Mitigation Update: Immediately upgrade to v1.6.0.
Audit: Review the wp_users table for any unauthorized administrators created recently, such as john_admin.
Cleanup: Remove any suspicious accounts found and rotate all legitimate administrator passwords.