Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
lu — la studio

lu — la studio Vendor Cyber Rating & Cyber Score

lu-la.studio

lu —— la (ludic — landscapes) is a landscape architecture and design studio specializing in playful spaces that foster connections to community and the natural world. Our design approach takes inspiration from the unique conditions of every site, thoughtfully responding to their invitations and challenges with well-considered materials and planting. Our process is sensitive to context and driven by narrative. We deliver designs that are anchored by a sense of place, and that inspire imagination and exploration. We believe that there is more to play than the climbing structure. Play can and should be layered into the landscape itself. We design our sites to create a rich field of opportunities that are as diverse as the people who


LLS A.I CyberSecurity Scoring

LLS
Company Information
Website:https://lu-la.studio/
Employees number:10
Number of followers:61
NAICS:5414
Industry Type:Design Services
Homepage:lu-la.studio
LLS Risk Score (AI oriented)
Between 750 and 799
logo
LLSDesign Services
Updated:
10/03/2026
752/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
LLS Global Score (TPRM)
xxxx
logo
LLSDesign Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

LLS
LLSFair
Current Score
752Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
752Before Incident
MAY 2026
752Before Incident
APRIL 2026
752Before Incident
MARCH 2026
752Before Incident
FEBRUARY 2026
752Before Incident
JANUARY 2026
752Before Incident
DECEMBER 2025
753Before Incident
Vulnerability
01 Dec 2025LLS
LA-Studio: 20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation

Critical Backdoor in LA-Studio Element Kit for Elementor Exposes 20,000+ WordPress Sites

751After Incident
CRITICAL-2
LU-1769200137
Critical Backdoor in LA-Studio Element Kit for Elementor Exposes 20,000+ WordPress Sites A severe backdoor vulnerability (CVE-2026-0920) has been discovered in the LA-Studio Element Kit for Elementor, a WordPress plugin with over 20,000 active installations. The flaw, rated 9.8 on the CVSS scale, allows unauthenticated attackers to create administrator accounts, enabling full site takeovers. The backdoor was introduced by a former LA-Studio employee who modified the plugin’s code before departing in late December 2025. The malicious functionality, hidden within the plugin’s user registration system, remained undetected until security researchers Athiwat Tiprasaharn, Itthidej Aramsri, and Waris Damkham identified it on January 12, 2026, via the Wordfence Bug Bounty Program. Exploitation occurs via a specially crafted registration request containing the `lakit_bkrole` parameter, granting attackers administrative privileges. Once exploited, they can upload malicious files, alter content, redirect visitors, or inject spam. The vulnerability affects all versions up to and including 1.5.6.3, with a patch (version 1.6.0) released on January 14, 2026. Wordfence analysts noted the backdoor was deliberately obfuscated using string manipulation and indirect function calls, making it difficult to detect during standard security reviews. The flaw specifically targeted the `ajax_register_handle` function, bypassing normal registration checks when the hidden parameter was present. Wordfence provided protection for Premium users on January 13, 2026, with free users receiving coverage on February 12, 2026. The incident underscores the risks of insider threats and the need for rigorous code review during employee transitions.
INCIDENT DETAILS -
TYPE
Backdoor
MOTIVATION
Insider threat
IMPACT
Systems Affected: 20,000+ WordPress sitesOperational Impact: Full site takeovers, malicious file uploads, content alteration, visitor redirection, spam injectionBrand Reputation Impact: Potential damage to LA-Studio and affected site owners
NOVEMBER 2025
753Before Incident
OCTOBER 2025
753Before Incident
SEPTEMBER 2025
753Before Incident
AUGUST 2025
753Before Incident
JULY 2025
753Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for LLS ?
?
What was LLS's A.I Rankiteo Cyber Score in May 2026 ?
?
What was LLS's A.I Rankiteo Cyber Score in April 2026 ?
?
What was LLS's A.I Rankiteo Cyber Score in March 2026 ?
?
What was LLS's A.I Rankiteo Cyber Score in February 2026 ?
?
What was LLS's A.I Rankiteo Cyber Score in January 2026 ?
?
What was LLS's A.I Rankiteo Cyber Score in December 2025 ?
?
What was LLS's A.I Rankiteo Cyber Score in November 2025 ?
?
What was LLS's A.I Rankiteo Cyber Score in October 2025 ?
?
What was LLS's A.I Rankiteo Cyber Score in September 2025 ?
?
What was LLS's A.I Rankiteo Cyber Score in August 2025 ?
?
What was LLS's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on LLS's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with LLS ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view LLS's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?