RTMKit
- < 2.0.9
A vulnerability exists in the RTMKit WordPress plugin in versions prior to 2.0.9, where an AJAX action fails to perform a proper capability check. This flaw allows users with at least the Contributor role to access the titles of other users' private, draft, pending, scheduled, and trashed posts by exploiting a request-supplied post identifier.
Exploitation of this vulnerability allows for unauthorized access to the titles of private and other restricted post types belonging to different users.
To reproduce this vulnerability, log in as a Contributor user and open the Elementor editor for any post that can be edited. Copy the `rtmkit_nonce` value from the post source. Then, send a POST request to `admin-ajax.php` with the action `get_specific_posts`, including the nonce and the ID of a private post owned by an administrator. The response will contain the title of the private post, demonstrating the successful exploitation of the vulnerability. This process can be repeated to access titles of other restricted posts.
Users are advised to update the RTMKit WordPress plugin to version 2.0.9 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.