Unrated severityNVD Advisory· Published Jul 16, 2026· Updated Jul 16, 2026
RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Template Creation and Activation
CVE-2026-12907
Description
The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to create and activate a site-wide template that overrides the header, footer or other global areas displayed to all visitors, which is normally restricted to administrators.
Affected products
1- Range: <2.0.9
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/61588303-d356-4cec-9cdc-15dc8cb0b29f/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.