Executive brief
The RTMKit plugin for WordPress, which provides design tools for the Elementor page builder, contains a security flaw that allows users with low-level 'Author' permissions to modify global website elements. An attacker with an Author account could replace the site's header, footer, or other global areas with their own content. This could be used to deface the website, display misleading information to all visitors, or disrupt the site's professional appearance.
Technical details
The RTMKit plugin (specifically the 'rometheme-for-elementor' component) suffers from a missing authorization check in its 'add_themebuilder' AJAX action. While the plugin's save handler ('edit_themebuilder') correctly requires 'manage_options' capabilities, the creation and activation handler does not. An authenticated user with at least the Author role can obtain a valid nonce from the Elementor editor and send a crafted POST request to 'admin-ajax.php'. This allows the attacker to create and activate site-wide templates for headers, footers, single posts, or 404 pages, effectively overriding global site areas normally restricted to administrators. The issue is fixed in version 2.0.9.
Affected products
- Rometheme RTMKit Addons for Elementor < 2.0.9
Timeline
- 2026-06-25: disclosed: Initial public disclosure by WPScan
- 2026-07-16: advisory: NVD publication date