Description
The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to create and activate a site-wide template that overrides the header, footer or other global areas displayed to all visitors, which is normally restricted to administrators.
Published: 2026-07-16
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from an Ajax endpoint that omits a proper capability check. An Author or higher role can trigger this action to create and activate a site‑wide template that overrides essential elements such as the header or footer, bypassing the administrator‑only restriction on global theme modifications; based on the description, it is inferred that this enables the attacker to deface the site, embed malicious content, or facilitate phishing. Based on the description, it is inferred that the ability to tamper with global site components can undermine user trust and serve as a conduit for more serious attacks when combined with other social engineering tactics. The weakness is an authorization bypass (CWE‑862) and can be exploited by any authenticated WordPress user with the Author role.

Affected Systems

The affected product is the RTMKit WordPress plugin, specifically the Addons for Elementor component released before version 2.0.9. Any WordPress site that has installed RTMKit Addons for Elementor with a version lower than 2.0.9 and that includes Author‑level users is at risk.

Risk and Exploitability

The CVSS score of 2.7 categorizes this issue as low severity and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalogue. The attack vector would be via a web‑based Ajax call that an authenticated Author role can send, so an attacker requires legitimate site credentials. Although the impact is limited to theme changes, the ability to tamper with global site components can undermine user trust and serve as a conduit for more serious attacks when combined with other social engineering tactics.

Generated by OpenCVE AI on July 31, 2026 at 02:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RTMKit Addons for Elementor to version 2.0.9 or later, which implements proper capability checks for all theme‑builder Ajax actions.
  • Revoke or remove the capability that allows authors to create and activate site‑wide templates by adjusting the role definitions in WordPress or using a role‑management plugin.
  • Review existing site‑wide templates for unauthorized changes and restore from backup if necessary.

Generated by OpenCVE AI on July 31, 2026 at 02:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to create and activate a site-wide template that overrides the header, footer or other global areas displayed to all visitors, which is normally restricted to administrators.
Title RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Template Creation and Activation
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-16T15:09:03.083Z

Reserved: 2026-06-22T14:41:44.233Z

Link: CVE-2026-12907

cve-icon Vulnrichment

Updated: 2026-07-16T15:06:46.270Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:30:05Z

Weaknesses