RTMKit
- < 2.0.9
A vulnerability exists in the RTMKit WordPress plugin in versions prior to 2.0.9, where the plugin fails to properly validate user capabilities on a specific theme-builder AJAX action. This flaw allows users with at least the Author role to create and activate a site-wide template that modifies the header, footer, or other global areas visible to all visitors. Such actions are typically reserved for administrators.
Exploitation of this vulnerability allows Authors to create and manage site-wide templates that override key global elements, such as headers and footers, affecting the appearance of the site for all users.
To reproduce this vulnerability, log in as a user with the Author role and open the Elementor editor for a post that can be edited. The RTMKit nonce required for the AJAX request can be found in the page source. Once the nonce is obtained, send a POST request to 'admin-ajax.php' with the action 'add_themebuilder', including the nonce, template title, type (header or footer), and activation status. After the request is processed, the newly created template will override the default site-wide header or footer, injecting content controlled by the Author.
Users are advised to update the RTMKit WordPress plugin to version 2.0.9 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.