Impact
The vulnerability in the Rometheme RTMKit WordPress plugin allows an attacker who manipulates a user-controlled key to bypass configured access‑control checks. This IDOR flaw can lead to unauthorized reading, modification or deletion of protected content, potentially exposing sensitive data or compromising site integrity. The weakness is identified as CWE‑639.
Affected Systems
All WordPress sites that have the RTMKit plugin installed from any version through 1.6.7 are affected. The plugin is distributed by Rometheme for the Elementor framework, and any installation using the affected versions is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of < 1% shows that exploitation attempts are currently very rare. The flaw is not listed in the CISA KEV catalog. Because the attack requires the attacker to control a key that is used to reference protected objects, the likely attack vector is remote and involves an authenticated user exploiting the plugin's URL or API endpoints to retrieve or manipulate resources they should not access.
OpenCVE Enrichment