Junglewise Threat Intelligence

CVE-2026-3426: RTMKit Addons for Elementor unauthorized data modification in widgets

CVE-2026-3426 · Severity: medium · CVSS 4.3 · Published 2026-05-13

Executive brief

The RTMKit Addons for Elementor plugin for WordPress, which provides additional design tools for website building, contains a security flaw that allows certain logged-in users to modify site settings. Specifically, users with 'Author' level permissions or higher can change or reset widget configurations across the entire website. This could lead to unauthorized changes to the site's appearance or layout, potentially disrupting the user experience or brand presentation.

Technical details

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized data modification due to missing authorization (CWE-862) in the save_widget() and reset_all_widgets() functions. These functions fail to implement proper capability checks, allowing authenticated attackers with Author-level permissions or higher to bypass intended restrictions. An attacker can exploit this over the network to modify or reset site-wide widget configurations. The vulnerability is present in all versions up to and including 2.0.2. A patch has been released in subsequent versions to address the missing capability checks.

Affected products

  • RTMKit RTMKit Addons for Elementor Up to, and including, 2.0.2

Timeline

  • 2026-05-13: disclosed: Initial disclosure by Wordfence
  • 2026-05-13: advisory: NVD publication date

References

Related threats