PT-2026-40594 · WordPress · Rtmkit Addons For Elementor
Momopon1415
·
Published
2026-05-13
·
Updated
2026-05-13
·
CVE-2026-3425
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RTMKit Addons for Elementor versions prior to 2.0.3
Description
The plugin is susceptible to Local File Inclusion (LFI), a condition where an application includes files on a server without proper validation. Authenticated attackers with Author-level access or higher can exploit the 'get content' AJAX action through the
path parameter to include and execute arbitrary PHP files. This may lead to the bypass of access controls, unauthorized access to sensitive data, or remote code execution if PHP files can be uploaded to the server.Recommendations
Update to a version later than 2.0.2.
As a temporary workaround, restrict access to the 'get content' AJAX action or the
path parameter for users with Author-level permissions.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rtmkit Addons For Elementor