Unrated severityNVD Advisory· Published Jul 16, 2026· Updated Jul 16, 2026
RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure
CVE-2026-12906
Description
The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private, draft, pending, scheduled and trashed posts.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/594c3769-b953-4966-836d-a0dc4585fe87/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.