RomethemeKit For Elementor <= 1.5.2 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates
Description
Authenticated attackers with Contributor-level access can extract private, pending, and draft template data from the RomethemeKit For Elementor plugin up to version 1.5.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated attackers with Contributor-level access can extract private, pending, and draft template data from the RomethemeKit For Elementor plugin up to version 1.5.2.
Vulnerability
The RomethemeKit For Elementor plugin for WordPress (also known as RTMKit [1]) contains a sensitive information exposure vulnerability in all versions up to and including 1.5.2. The flaw resides in the register_controls function within widgets/offcanvas-rometheme.php. This allows authenticated users with at least Contributor-level access to extract sensitive private, pending, and draft template data.
Exploitation
An attacker must have a WordPress account with Contributor-level privileges or higher. No additional authentication or special conditions are required beyond being logged in. The attacker can trigger the vulnerable code path by interacting with the offcanvas widget controls, which exposes the restricted template data without proper authorization checks.
Impact
Successful exploitation results in the disclosure of sensitive template data, including private, pending, and draft templates. This information exposure can reveal unpublished content, potentially including confidential business information or pre-release designs. The attacker gains read access to data that should be restricted to higher-privileged users.
Mitigation
The vulnerability is fixed in version 2.0.7 of the plugin [1]. Users are strongly advised to update to the latest version immediately. No workarounds are available for versions 1.5.2 and earlier. The plugin is actively maintained, and the update can be obtained from the WordPress plugin repository.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.5.2
Patches
1Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.