PT-2026-40594 · WordPress · Rtmkit Addons For Elementor

Momopon1415

·

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2026-3425

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RTMKit Addons for Elementor versions prior to 2.0.3
Description The plugin is susceptible to Local File Inclusion (LFI), a condition where an application includes files on a server without proper validation. Authenticated attackers with Author-level access or higher can exploit the 'get content' AJAX action through the path parameter to include and execute arbitrary PHP files. This may lead to the bypass of access controls, unauthorized access to sensitive data, or remote code execution if PHP files can be uploaded to the server.
Recommendations Update to a version later than 2.0.2. As a temporary workaround, restrict access to the 'get content' AJAX action or the path parameter for users with Author-level permissions.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3425

Affected Products

Rtmkit Addons For Elementor