Rometheme
Rometheme Rtmkit: vulnerabilities and CVEs
Rometheme Rtmkit has 8 published vulnerabilities, 3 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs8
Last 12 months3
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5137 | Medium (4.3) | 0.45% | — | Jul 3, 2026 | The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7 This is due to insufficient path validation on the 'template' parameter in the… |
| CVE-2025-62065 | Critical (9.9) | 0.31% | — | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue affects RTMKit: from n/a through <= 1.6.5. |
| CVE-2025-64283 | Medium (6.5) | 0.27% | — | Oct 29, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Rometheme RTMKit rometheme-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RTMKit: from n/a… |
| CVE-2025-49235 | Medium (6.5) | 0.25% | — | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Stored XSS.This issue affects RTMKit: from n/a through <= 1.6.0. |
| CVE-2025-30911 | Critical (9.9) | 1.9% | — | Apr 1, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This issue affects RTMKit: from n/a through <= 1.5.4. |
| CVE-2025-24743 | Medium (4.3) | 0.26% | — | Jan 27, 2025 | Missing Authorization vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue affects RTMKit: from n/a through <= 1.5.2. |
| CVE-2024-47626 | Medium (6.5) | 0.26% | — | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Stored XSS.This issue affects RTMKit: from n/a through <= 1.5.0. |
| CVE-2024-32956 | Medium (6.5) | 0.32% | — | Apr 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue affects RTMKit: from n/a through <= 1.4.1. |