CVE-2024-32956
Description
A stored cross-site scripting vulnerability in Rometheme RTMKit (rometheme-for-elementor) allows unauthenticated attackers to inject arbitrary web scripts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stored cross-site scripting vulnerability in Rometheme RTMKit (rometheme-for-elementor) allows unauthenticated attackers to inject arbitrary web scripts.
Vulnerability
The Rometheme RTMKit plugin for WordPress (rometheme-for-elementor) versions up to and including 1.4.1 are vulnerable to stored cross-site scripting (XSS) due to improper neutralization of input during web page generation [1]. The vulnerability exists in the plugin's widget rendering, where user-supplied input is not properly sanitized before being stored and later executed in the context of an administrator's browser session.
Exploitation
An unauthenticated attacker can exploit this vulnerability by submitting crafted input through a vulnerable form or widget that accepts user data. The injected script is stored on the server and subsequently executed when an administrator views the affected page or post in the WordPress admin panel [1]. No special permissions or authentication are required to submit the malicious payload.
Impact
Successful exploitation allows an attacker to inject arbitrary JavaScript or HTML into the admin interface, leading to potential session hijacking, defacement, or theft of sensitive information disclosed to authenticated users. The attack is executed in the context of the administrator's browser, which can result in privilege escalation or complete site compromise [1].
Mitigation
The vulnerability is fixed in version 2.0.7, released on 2026-04-20 [1]. Users should update the RTMKit plugin to version 2.0.7 or later immediately. No workaround is available for earlier versions, and sites running vulnerable versions should consider disabling the plugin until the update is applied.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.4.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- patchstack.com/database/Wordpress/Plugin/rometheme-for-elementor/vulnerability/wordpress-romethemekit-for-elementor-plugin-1-4-1-cross-site-scripting-xss-vulnerabilitynvd
- patchstack.com/database/vulnerability/rometheme-for-elementor/wordpress-romethemekit-for-elementor-plugin-1-4-1-cross-site-scripting-xss-vulnerabilitynvd
News mentions
0No linked articles in our index yet.