Impact
The vulnerability originates from an Ajax endpoint that omits a proper capability check. An Author or higher role can trigger this action to create and activate a site‑wide template that overrides essential elements such as the header or footer, bypassing the administrator‑only restriction on global theme modifications; based on the description, it is inferred that this enables the attacker to deface the site, embed malicious content, or facilitate phishing. Based on the description, it is inferred that the ability to tamper with global site components can undermine user trust and serve as a conduit for more serious attacks when combined with other social engineering tactics. The weakness is an authorization bypass (CWE‑862) and can be exploited by any authenticated WordPress user with the Author role.
Affected Systems
The affected product is the RTMKit WordPress plugin, specifically the Addons for Elementor component released before version 2.0.9. Any WordPress site that has installed RTMKit Addons for Elementor with a version lower than 2.0.9 and that includes Author‑level users is at risk.
Risk and Exploitability
The CVSS score of 2.7 categorizes this issue as low severity and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalogue. The attack vector would be via a web‑based Ajax call that an authenticated Author role can send, so an attacker requires legitimate site credentials. Although the impact is limited to theme changes, the ability to tamper with global site components can undermine user trust and serve as a conduit for more serious attacks when combined with other social engineering tactics.
OpenCVE Enrichment