LLS A.I CyberSecurity Scoring
LLS
Company Information
Website:https://lu-la.studio/
Employees number:10
Number of followers:61
NAICS:5414
Industry Type:Design Services
Homepage:lu-la.studio
LLS Risk Score (AI oriented)
Between 750 and 799
LLSDesign Services
Updated:
10/03/2026
10/03/2026
752/1000
Fair
Baa
LLS Global Score (TPRM)
xxxx
LLSDesign Services
Score locked

LLSFair
Current Score
752Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
752
MAY 2026
752
APRIL 2026
752
MARCH 2026
752
FEBRUARY 2026
752
JANUARY 2026
752
DECEMBER 2025
753
Vulnerability
01 Dec 2025 • LLS
LA-Studio: 20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation
Critical Backdoor in LA-Studio Element Kit for Elementor Exposes 20,000+ WordPress Sites
751
CRITICAL-2
LU-1769200137
Critical Backdoor in LA-Studio Element Kit for Elementor Exposes 20,000+ WordPress Sites
A severe backdoor vulnerability (CVE-2026-0920) has been discovered in the LA-Studio Element Kit for Elementor, a WordPress plugin with over 20,000 active installations. The flaw, rated 9.8 on the CVSS scale, allows unauthenticated attackers to create administrator accounts, enabling full site takeovers.
The backdoor was introduced by a former LA-Studio employee who modified the plugin’s code before departing in late December 2025. The malicious functionality, hidden within the plugin’s user registration system, remained undetected until security researchers Athiwat Tiprasaharn, Itthidej Aramsri, and Waris Damkham identified it on January 12, 2026, via the Wordfence Bug Bounty Program.
Exploitation occurs via a specially crafted registration request containing the `lakit_bkrole` parameter, granting attackers administrative privileges. Once exploited, they can upload malicious files, alter content, redirect visitors, or inject spam. The vulnerability affects all versions up to and including 1.5.6.3, with a patch (version 1.6.0) released on January 14, 2026.
Wordfence analysts noted the backdoor was deliberately obfuscated using string manipulation and indirect function calls, making it difficult to detect during standard security reviews. The flaw specifically targeted the `ajax_register_handle` function, bypassing normal registration checks when the hidden parameter was present.
Wordfence provided protection for Premium users on January 13, 2026, with free users receiving coverage on February 12, 2026. The incident underscores the risks of insider threats and the need for rigorous code review during employee transitions.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
NOVEMBER 2025
753
OCTOBER 2025
753
SEPTEMBER 2025
753
AUGUST 2025
753
JULY 2025
753
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for LLS ??
What was LLS's A.I Rankiteo Cyber Score in May 2026 ??
What was LLS's A.I Rankiteo Cyber Score in April 2026 ??
What was LLS's A.I Rankiteo Cyber Score in March 2026 ??
What was LLS's A.I Rankiteo Cyber Score in February 2026 ??
What was LLS's A.I Rankiteo Cyber Score in January 2026 ??
What was LLS's A.I Rankiteo Cyber Score in December 2025 ??
What was LLS's A.I Rankiteo Cyber Score in November 2025 ??
What was LLS's A.I Rankiteo Cyber Score in October 2025 ??
What was LLS's A.I Rankiteo Cyber Score in September 2025 ??
What was LLS's A.I Rankiteo Cyber Score in August 2025 ??
What was LLS's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on LLS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with LLS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view LLS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?