The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_options and reset_widgets functions in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify plugin settings or reset plugin widgets to their default state (all enabled). NOTE: This vulnerability was partially fixed in version 1.5.3.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54129 | The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_options and reset_widgets functions in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify plugin settings or reset plugin widgets to their default state (all enabled). NOTE: This vulnerability was partially fixed in version 1.5.3. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 12 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rometheme
Rometheme romethemekit For Elementor |
|
| CPEs | cpe:2.3:a:rometheme:romethemekit_for_elementor:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Rometheme
Rometheme romethemekit For Elementor |
Tue, 11 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 08 Mar 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_options and reset_widgets functions in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify plugin settings or reset plugin widgets to their default state (all enabled). NOTE: This vulnerability was partially fixed in version 1.5.3. | |
| Title | RomethemeKit For Elementor <= 1.5.3 - Missing Authorization in save_options and reset_widgets | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-03-11T16:07:02.799Z
Reserved: 2024-10-23T23:07:45.983Z
Link: CVE-2024-10326
Updated: 2025-03-10T16:56:44.047Z
Status : Analyzed
Published: 2025-03-08T13:15:11.050
Modified: 2025-03-12T16:24:13.393
Link: CVE-2024-10326
No data.
OpenCVE Enrichment
No data.
EUVD