Rometheme / RTMKit
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-62133 | WordPress RTMKit plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability | MEDIUM | 5.4 | Sep 11, 2026 |
| CVE-2026-84763 | WordPress RTMKit plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | Sep 3, 2026 |
| CVE-2026-84752 | WordPress RTMKit plugin <= 2.1.5 - PHP Object Injection vulnerability | HIGH | 8.8 | Sep 3, 2026 |
| CVE-2026-5137 | RTMKit <= 2.0.7 - Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter | MEDIUM | 4.3 | Jul 3, 2026 |
| CVE-2026-8351 | RTMKit <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' Parameter | MEDIUM | 6.4 | Jul 3, 2026 |
| CVE-2026-5149 | RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter | MEDIUM | 6.5 | Jun 16, 2026 |
| CVE-2026-3426 | RTMKit Addons for Elementor <= 2.0.2 - Authenticated (Author+) Missing Authorization to Widget Configuration Modification | MEDIUM | 4.3 | May 13, 2026 |
| CVE-2026-3425 | RTMKit Addons for Elementor <= 2.0.2 - Authenticated (Author+) Local File Inclusion via 'path' | HIGH | 8.8 | May 13, 2026 |
| CVE-2025-12473 | RTMKit <= 1.6.8 - Reflected Cross-Site Scripting via 'themebuilder' Parameter | MEDIUM | 6.1 | Mar 11, 2026 |
| CVE-2025-8609 | RTMKit Addons <= 1.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Repeater Block Attribute | MEDIUM | 6.4 | Nov 18, 2025 |
| CVE-2025-62065 | WordPress RTMKit plugin <= 1.6.5 - Arbitrary File Upload vulnerability | CRITICAL | 9.9 | Nov 6, 2025 |
| CVE-2025-64283 | WordPress RTMKit plugin <= 1.6.7 - Insecure Direct Object References (IDOR) vulnerability | MEDIUM | 6.5 | Oct 29, 2025 |
| CVE-2025-49235 | WordPress RTMKit Addons for Elementor plugin <= 1.6.0 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | Jun 6, 2025 |
| CVE-2025-30911 | WordPress RomethemeKit For Elementor plugin <= 1.5.4 - Arbitrary Plugin Installation/Activation to RCE vulnerability | CRITICAL | 9.9 | Apr 1, 2025 |
| CVE-2024-10326 | RomethemeKit For Elementor <= 1.5.3 - Missing Authorization in save_options and reset_widgets | MEDIUM | 4.3 | Mar 8, 2025 |
| CVE-2025-24743 | WordPress RomethemeKit For Elementor plugin <= 1.5.2 - Broken Access Control vulnerability | MEDIUM | 4.3 | Jan 27, 2025 |
| CVE-2024-10324 | RomethemeKit For Elementor <= 1.5.2 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates | MEDIUM | 4.3 | Jan 24, 2025 |
Showing 1 to 17 of 17 CVEs