A critical backdoor was identified in the LA-Studio Element Kit for Elementor WordPress plugin (active on 20,000+ sites), enabling unauthenticated attackers to create administrator accounts and take full control of affected websites. The issue is tracked as CVE-2026-0920 with a CVSS 9.8 rating, and exploitation has been reported in the wild. The malicious logic was embedded in the plugin’s registration flow, allowing attackers to elevate privileges during account creation and then perform typical admin-level actions such as uploading malicious files, injecting spam, or redirecting visitors.
Technical reporting attributes the backdoor to sabotage: the vendor stated the malicious code was planted by a former employee, with changes occurring around the time their employment ended. The vulnerable path is the ajax_register_handle() function, where attackers can supply a specific registration parameter, lakit_bkrole, to obtain administrator capability; the code was described as obfuscated to evade detection. CVE documentation characterizes the weakness as improper restriction of user role assignment during registration (mapped to CWE-269) and points to the affected versions up to and including 1.5.6.3, along with upstream code references and the associated Wordfence advisory.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Wordfence said protection for free-tier users would become available on February 12, 2026, after Premium users had already received coverage. This marked the broader rollout of defensive coverage for sites still running vulnerable plugin versions.
Wordfence said attackers were actively exploiting the backdoor and that it blocked 216 attack attempts in a 24-hour period. Public reporting also highlighted the vendor's claim that the issue stemmed from insider sabotage by a former employee.
The vulnerability was assigned CVE-2026-0920 and the CVE record notes it was received by security@wordfence.com on January 22, 2026. The entry described the flaw as unauthenticated privilege escalation through improper role restriction in ajax_register_handle().
LA-Studio issued a patch in plugin version 1.6.0 to fix the vulnerability and remove the malicious code. Users were urged to update immediately because affected versions were installed on more than 20,000 WordPress sites.
Wordfence notified the vendor about the backdoor vulnerability and began protecting Premium users against exploitation. The issue was already being treated as critical because it enabled full site takeover through unauthenticated admin creation.
Researchers discovered the vulnerability in LA-Studio Element Kit for Elementor and reported it through the Wordfence Bug Bounty Program. The flaw affected versions up to and including 1.5.6.3 and allowed unauthenticated administrator account creation via the lakit_bkrole parameter.
LA-Studio said a former employee intentionally introduced obfuscated backdoor logic into the Element Kit for Elementor plugin shortly before leaving in late December 2025. The code allowed a hidden registration parameter to assign administrator privileges to a newly created user.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.