Skip to content

20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation

Cybersecuritynews •Tushar Subhra Dutta • January 23, 2026

A critical backdoor vulnerability has been discovered in the LA-Studio Element Kit for Elementor, a popular WordPress plugin used by more than 20,000 active sites. This security flaw allows attackers to create administrator accounts without any authentication, putting thousands of websites at risk of complete takeover. The vulnerability, tracked as CVE-2026-0920, carries a CVSS score […]

Extracted Entities

CVEs (1)

Platforms (2)