Impact
Missing authorization in Rometheme RTMKit plugin for WordPress allows an attacker to bypass access controls and perform actions that should be restricted to authenticated or privileged users. This broken access control can lead to unauthorized modification or deletion of content, or execution of privileged administrative functions, compromising the integrity and confidentiality of the WordPress site. The weakness is classified as CWE‑862, representing improper authorization.
Affected Systems
This flaw affects the WordPress plugin Rometheme RTMKit (sometimes listed as Rometheme for Elementor) distributed by Rometheme. All released versions from the earliest available through 1.5.2 are vulnerable.
Risk and Exploitability
The CVSS score is 4.3, indicating a medium severity overall, while the EPSS score is less than 1%, suggesting a low probability of exploitation at this time. The plugin runs inside WordPress, so the vulnerability can be leveraged remotely by sending specially crafted requests to the plugin’s admin endpoints. The vulnerability is not currently listed in CISA’s KEV catalog, and no publicly reported exploitation has been documented. The primary risk is an attacker gaining unauthorized access to administrative functions or sensitive content within a WordPress site that hosts the vulnerable plugin.
OpenCVE Enrichment
EUVD