Junglewise Threat Intelligence

CVE-2026-3425: RTMKit Addons for Elementor Local File Inclusion in get_content AJAX action

CVE-2026-3425 · Severity: high · CVSS 8.8 · Published 2026-05-13

Executive brief

The RTMKit Addons for Elementor plugin for WordPress, which provides additional design elements for website building, contains a security flaw that allows certain logged-in users to run malicious code on the server. An attacker with Author-level permissions or higher could exploit this to access sensitive files, take control of the website, or disrupt operations. This poses a significant risk to data confidentiality and the overall integrity of the web server.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the RTMKit Addons for Elementor plugin due to insufficient validation of the 'path' parameter within the 'get_content' AJAX action. The flaw is located in the PluginApi.php file. Authenticated attackers with Author-level privileges or higher can exploit this by submitting a crafted request to include and execute arbitrary PHP files already present on the server. If an attacker can successfully upload a malicious file (e.g., via a separate upload vulnerability or legitimate feature), this LFI can be escalated to full Remote Code Execution (RCE). A patch has been identified in changeset 3474369.

Affected products

  • RTMKit RTMKit Addons for Elementor Up to, and including, 2.0.2

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References

Related threats