CVE-2026-0920PoC

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.6.3. This is due to the 'ajax_register_handle' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'lakit_bkrole' parameter during registration and gain administrator access to the site.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-01-30); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-01-29: 1Mentions · 2026-01-30: 2Mentions · 2026-02-13: 1PoC Mentioned / Linked · 2026-01-29: 1Exploit Tool / Code · 2026-01-29: 1Active Exploitation · 2026-01-30: 1Patch / Workaround · 2026-02-13: 1Technical Details · 2026-01-29: 1Technical Details · 2026-01-30: 1Technical Details · 2026-02-13: 101-2901-3002-13
Signal classification4 categories
PoC
125.0%
Active Exploitation
125.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-01-291
PoC1
2026-01-302
Active Exploitation1Disclosure1
2026-02-131
Patch1
Full discourse4 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-0920: Explanation and payload of the recent vulnerability in the LA-Studio Element WordPress plugin. PoC/Exploit: https://github.com/John-doe-code-a11/CVE-2026-0920 CVSS: 9.8 CVE Published: January 22nd, 2026 Advisory: https://github.com/advisories/GHSA-m3h4-65j5-6j8c https://t.co/bNdGcLI8PT

    Post summary

    The post announces CVE-2026-0920, providing a PoC/exploit link, technical vulnerability details, and a high CVSS score, but no evidence of active exploitation or patches.

    113041165.1K
    165.7K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    WordPress LA-Studio Kit の脆弱性 CVE-2026-0920 が FIX:バックドアとサイト乗っ取り https://iototsecnews.jp/2026/01/23/20000-wordpress-sites-compromised-by-backdoor-vulnerability-enabling-malicious-admin-access/ WordPress の人気プラグイン Elementor のエクステンション LA-Studio Element Kit において、システムの完全な乗っ取りを許す可能性のある、きわめて深刻な脆弱性 CVE-2026-0920 が発見されました。この問題で特筆すべきは、外部からの攻撃が起こり得るという点だけではなく、開発元の元従業員により意図的にバックドアが仕込まれていたというインサイダー脅威にあります。 この脆弱性は、ユーザー登録時の権限割り当て処理の不備に起因します。それを悪用する攻撃者は、登録リクエストに特定のパラメータ “lakit_bkrole” を取り込むだけで、本来は一般ユーザーとして登録されるはずの自分自身に、サイトの管理者権限を付与できてしまいます。ご利用のチームは、ご注意ください。 #CVE20260920 #Elementor #LAStudioKit #Vulnerability #WordPress

    Post summary

    The article reports that CVE-2026-0920, a critical WordPress plugin vulnerability, has already been exploited in the wild, compromising around 20,000 sites via a backdoor that grants admin rights during user registration. No patch or PoC is provided.

    01000199
    485 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    CVE-2026-0920 — Critical WordPress Plugin Vulnerability https://nvd.nist.gov/vuln/detail/CVE-2026-0920 The LA-Studio Element Kit for Elementor plugin (≤ 1.5.6.3) allows unauthenticated attackers to create admin accounts. No login required. Full site takeover possible. If this plugin is installed: • Update immediately • Audit admin users • Scan for backdoors Attackers move fast after public disclosure. 🔗 https://quttera.com/wordpress-malware-scanner #WordPressSecurity #CyberThreats #Malware #WordPress #CVE

    Post summary

    CVE-2026-0920 is a critical WordPress plugin vulnerability that permits unauthenticated creation of admin accounts, enabling full site takeover; users are urged to update the plugin immediately and audit for backdoors.

    0000047
    37 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en complemento de WordPress ❗ CVE-2026-0920 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-complemento-de-wordpress-6/ https://t.co/gcyY7KOsMZ

    Post summary

    A newly reported WordPress plugin vulnerability, CVE-2026-0920, has been announced with a link to a CERT advisory for additional details.

    00000115
    6.6K followersView on X

Explore more