RomethemeKit For Elementor, CVE-2026-5149
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jun 16, 2026
- Research Description
- The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submission_content AJAX endpoint lacking a capability check to verify that a user has permission to access the requested form submission data. This makes it possible for authenticated attackers, with Contributor-level access and above, to view arbitrary form submissions from other users by iterating the entries_id parameter.
- Affected versions
-
max 2.0.8.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| WooCommerce Digital Signature (CVE-2026-52694) , Jun 17, 2026 |