VYPR
Unrated severityNVD Advisory· Published Jan 24, 2025· Updated Apr 8, 2026

RomethemeKit For Elementor <= 1.5.2 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates

CVE-2024-10324

Description

Authenticated attackers with Contributor-level access can extract private, pending, and draft template data from the RomethemeKit For Elementor plugin up to version 1.5.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated attackers with Contributor-level access can extract private, pending, and draft template data from the RomethemeKit For Elementor plugin up to version 1.5.2.

Vulnerability

The RomethemeKit For Elementor plugin for WordPress (also known as RTMKit [1]) contains a sensitive information exposure vulnerability in all versions up to and including 1.5.2. The flaw resides in the register_controls function within widgets/offcanvas-rometheme.php. This allows authenticated users with at least Contributor-level access to extract sensitive private, pending, and draft template data.

Exploitation

An attacker must have a WordPress account with Contributor-level privileges or higher. No additional authentication or special conditions are required beyond being logged in. The attacker can trigger the vulnerable code path by interacting with the offcanvas widget controls, which exposes the restricted template data without proper authorization checks.

Impact

Successful exploitation results in the disclosure of sensitive template data, including private, pending, and draft templates. This information exposure can reveal unpublished content, potentially including confidential business information or pre-release designs. The attacker gains read access to data that should be restricted to higher-privileged users.

Mitigation

The vulnerability is fixed in version 2.0.7 of the plugin [1]. Users are strongly advised to update to the latest version immediately. No workarounds are available for versions 1.5.2 and earlier. The plugin is actively maintained, and the update can be obtained from the WordPress plugin repository.

References
  1. RTMKit

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

1

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.