Low severity2.7NVD Advisory· Published Jul 16, 2026· Updated Jul 16, 2026
CVE-2026-12907
CVE-2026-12907
Description
The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to create and activate a site-wide template that overrides the header, footer or other global areas displayed to all visitors, which is normally restricted to administrators.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.