Junglewise Threat Intelligence

CVE-2026-5149: RomeTheme RTMKit incorrect authorization in get_submission_content

CVE-2026-5149 · Severity: medium · CVSS 6.5 · Published 2026-06-16

Technologies: RomeTheme RTMKit. Vendors: RomeTheme.

Executive brief

The RTMKit plugin for WordPress, which provides additional features for the Elementor page builder, contains a security flaw that allows unauthorized users to view private form submissions. An attacker with a basic contributor account on the website could access sensitive information submitted by other users through contact forms. This could lead to the exposure of personal data or confidential business inquiries.

Technical details

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization (CWE-863) in versions up to 2.0.7. The vulnerability exists within the 'get_submission_content' AJAX endpoint, which fails to implement a proper capability check to verify user permissions before returning form data. An authenticated attacker with at least Contributor-level privileges can exploit this by sending requests to the endpoint and iterating through the 'entries_id' parameter to retrieve arbitrary form submissions from other users. The issue is addressed in version 2.0.8.

Affected products

  • RomeTheme RTMKit (RomeTheme for Elementor) up to, and including, 2.0.7

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory

References

Related threats