LDS A.I CyberSecurity Scoring
LDS
Company Information
Website:https://www.ladesignstudio.com
Employees number:6
Number of followers:22
NAICS:541613
Industry Type:Advertising Services
Homepage:ladesignstudio.com
LDS Risk Score (AI oriented)
Between 750 and 799
LDSAdvertising Services
Updated:
09/03/2026
09/03/2026
754/1000
Fair
Baa
LDS Global Score (TPRM)
xxxx
LDSAdvertising Services
Score locked

LDSFair
Current Score
754Baa (FAIR)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
755
MAY 2026
755
APRIL 2026
755
MARCH 2026
754
FEBRUARY 2026
754
JANUARY 2026
754
DECEMBER 2025
755
Vulnerability
01 Dec 2025 • LDS
LA-Studio: 20,000 WordPress Sites Compromised by Backdoor Vulnerability Enabling Malicious Admin Access
Critical Backdoor in LA-Studio Element Kit for Elementor Exposes 20,000+ WordPress Sites
754
CRITICAL-1
L-A1769207278
Critical Backdoor in LA-Studio Element Kit for Elementor Exposes 20,000+ WordPress Sites
A severe backdoor vulnerability (CVE-2026-0920, CVSS 9.8) in the LA-Studio Element Kit for Elementor plugin has left over 20,000 WordPress installations vulnerable to unauthenticated attacks. The flaw allows attackers to create administrator accounts and fully compromise affected sites by exploiting the `lakit_bkrole` parameter during user registration, bypassing role restrictions.
The malicious code, deliberately obfuscated, was traced to a former LA-Studio employee who injected it before departing in December 2025. The vulnerability resides in the `ajax_register_handle` function within the `LA-Studio_Kit_Integration` class, enabling attackers to upload malicious files, alter content, inject spam, or redirect visitors to phishing sites all without authentication.
Security firm Wordfence discovered the flaw on January 12, 2026, validating the exploit within 24 hours. LA-Studio responded swiftly, releasing a patched version (1.6.0) on January 14, 2026. Researchers Athiwat Tiprasaharn, Itthidej Aramsri, and Waris Damkham earned a $975 bounty for the responsible disclosure.
Protection measures were rolled out in phases: Wordfence Premium, Care, and Response users received firewall rules on January 13, 2026, while free users will gain access on February 12, 2026. The incident highlights risks posed by insider threats and underscores the need for stricter code audits, developer monitoring, and offboarding protocols in plugin development. Site administrators are advised to update immediately to version 1.6.0 to mitigate the threat.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
755
OCTOBER 2025
755
SEPTEMBER 2025
755
AUGUST 2025
755
JULY 2025
755
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for LDS ??
What was LDS's A.I Rankiteo Cyber Score in May 2026 ??
What was LDS's A.I Rankiteo Cyber Score in April 2026 ??
What was LDS's A.I Rankiteo Cyber Score in March 2026 ??
What was LDS's A.I Rankiteo Cyber Score in February 2026 ??
What was LDS's A.I Rankiteo Cyber Score in January 2026 ??
What was LDS's A.I Rankiteo Cyber Score in December 2025 ??
What was LDS's A.I Rankiteo Cyber Score in November 2025 ??
What was LDS's A.I Rankiteo Cyber Score in October 2025 ??
What was LDS's A.I Rankiteo Cyber Score in September 2025 ??
What was LDS's A.I Rankiteo Cyber Score in August 2025 ??
What was LDS's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on LDS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with LDS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view LDS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?