Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

RTMKit — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in RTMKit, with AI-generated Chinese analysis, references, and POCs.

The RTMKit Vulnerability Aggregation Page compiles known security weaknesses associated with the RTMKit product. This resource focuses on aggregating data related to common weakness types and specific product tags to provide a centralized view of risk. The page collects vulnerability data spanning a comprehensive time range, ensuring that both historical findings and recent disclosures are accessible for thorough security analysis. By utilizing this interface, users can effectively track vendor advisories as they are published, allowing for timely response and remediation planning. Additionally, the page facilitates a deeper understanding of specific weakness classes by contextualizing them within the RTMKit ecosystem, helping security professionals identify patterns and root causes. Users may also look up the product's vulnerability history to assess long-term security posture and maintenance trends over time. This tool is designed to support informed decision-making by presenting structured, searchable data without the noise of unrelated information. The aggregation aims to bridge the gap between raw vulnerability feeds and actionable intelligence, enabling teams to prioritize risks based on severity and relevance to their specific deployment of RTMKit. By consolidating these details, the page serves as a reference point for researchers, auditors, and developers seeking to mitigate exposure and enhance the overall security resilience of systems utilizing RTMKit.

Vendor: Rometheme

CVE ID Title CVSS Severity Published
CVE-2026-12907 RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Template Creation and Activation - - 2026-07-16
CVE-2026-12906 RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure - - 2026-07-16
CVE-2026-5137 RTMKit <= 2.0.7 - Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter CWE-98 4.3 Medium 2026-07-03
CVE-2026-8351 RTMKit <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' Parameter CWE-79 6.4 Medium 2026-07-03
CVE-2026-5149 RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter CWE-863 6.5 Medium 2026-06-16
CVE-2026-3426 RTMKit Addons for Elementor <= 2.0.2 - Authenticated (Author+) Missing Authorization to Widget Configuration Modification CWE-862 4.3 Medium 2026-05-13
CVE-2026-3425 RTMKit Addons for Elementor <= 2.0.2 - Authenticated (Author+) Local File Inclusion via 'path' CWE-98 8.8 High 2026-05-13
CVE-2025-12473 RTMKit <= 1.6.8 - Reflected Cross-Site Scripting via 'themebuilder' Parameter CWE-79 6.1 Medium 2026-03-11
CVE-2025-8609 RTMKit Addons <= 1.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Repeater Block Attribute CWE-79 6.4 Medium 2025-11-18
CVE-2025-62065 WordPress RTMKit plugin <= 1.6.5 - Arbitrary File Upload vulnerability CWE-434 9.9 Critical 2025-11-06
CVE-2025-64283 WordPress RTMKit plugin <= 1.6.7 - Insecure Direct Object References (IDOR) vulnerability CWE-639 6.5 Medium 2025-10-29
CVE-2025-49235 WordPress RTMKit Addons for Elementor plugin <= 1.6.0 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2025-06-06
CVE-2025-30911 WordPress RomethemeKit For Elementor plugin <= 1.5.4 - Arbitrary Plugin Installation/Activation to RCE vulnerability CWE-94 9.9 Critical 2025-04-01
CVE-2024-10326 RomethemeKit For Elementor <= 1.5.3 - Missing Authorization in save_options and reset_widgets CWE-862 4.3 Medium 2025-03-08
CVE-2025-24743 WordPress RomethemeKit For Elementor plugin <= 1.5.2 - Broken Access Control vulnerability CWE-862 4.3 Medium 2025-01-27
CVE-2024-10324 RomethemeKit For Elementor <= 1.5.2 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates CWE-1230 4.3 Medium 2025-01-24
CVE-2024-47626 WordPress RomethemeKit For Elementor plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-10-05
CVE-2024-32956 WordPress RomethemeKit For Elementor plugin <= 1.4.1 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-04-24

All 18 known CVE vulnerabilities affecting RTMKit with full Chinese analysis, references, and POCs where available.