Executive brief
The RTMKit Addons for Elementor plugin for WordPress, which provides additional design elements for website building, contains a security flaw that allows certain logged-in users to run malicious code on the server. An attacker with Author-level permissions or higher could exploit this to access sensitive files, take control of the website, or disrupt operations. This poses a significant risk to data confidentiality and the overall integrity of the web server.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the RTMKit Addons for Elementor plugin due to insufficient validation of the 'path' parameter within the 'get_content' AJAX action. The flaw is located in the PluginApi.php file. Authenticated attackers with Author-level privileges or higher can exploit this by submitting a crafted request to include and execute arbitrary PHP files already present on the server. If an attacker can successfully upload a malicious file (e.g., via a separate upload vulnerability or legitimate feature), this LFI can be escalated to full Remote Code Execution (RCE). A patch has been identified in changeset 3474369.
Affected products
- RTMKit RTMKit Addons for Elementor Up to, and including, 2.0.2
Timeline
- 2026-05-13: disclosed
- 2026-05-13: advisory