Authorization Bypass in Rometheme RTMKit Plugin for Elementor
CVE-2025-64283
6.5MEDIUM
What is CVE-2025-64283?
The Rometheme RTMKit plugin for Elementor contains an authorization bypass vulnerability that can be exploited due to improperly configured access control security levels. An attacker can leverage this weakness to gain unauthorized access to sensitive resources within WordPress installations, impacting the overall security posture of affected websites. This vulnerability affects RTMKit versions up to and including 1.6.7.
Affected Version(s)
RTMKit <= n/a