VYPR

RTMKit

by WordPress

CVEs (1)

  • CVE-2026-5149MedJun 16, 2026
    risk 0.35cvss 6.5epss

    The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submission_content AJAX endpoint lacking a capability check to verify that a user has permission to access the requested form submission…