RTMKit WordPress Plugin Missing Capability Check Vulnerability on Theme Builder AJAX Action

Vulnerability

A vulnerability exists in the RTMKit WordPress plugin in versions prior to 2.0.9, where the plugin fails to properly validate user capabilities on a specific theme-builder AJAX action. This flaw allows users with at least the Author role to create and activate a site-wide template that modifies the header, footer, or other global areas visible to all visitors. Such actions are typically reserved for administrators.

Impact

Exploitation of this vulnerability allows Authors to create and manage site-wide templates that override key global elements, such as headers and footers, affecting the appearance of the site for all users.

Reproduction

To reproduce this vulnerability, log in as a user with the Author role and open the Elementor editor for a post that can be edited. The RTMKit nonce required for the AJAX request can be found in the page source. Once the nonce is obtained, send a POST request to 'admin-ajax.php' with the action 'add_themebuilder', including the nonce, template title, type (header or footer), and activation status. After the request is processed, the newly created template will override the default site-wide header or footer, injecting content controlled by the Author.

Remediation

Users are advised to update the RTMKit WordPress plugin to version 2.0.9 or later.

Added: Jul 16, 2026, 7:24 AM
Updated: Jul 16, 2026, 7:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.6
remediation
0.0
relevance
9.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.