Local File Inclusion Vulnerability in RTMKit Addons for Elementor Plugin
CVE-2026-3425
8.8HIGH
What is CVE-2026-3425?
The RTMKit Addons for Elementor plugin for WordPress presents a Local File Inclusion vulnerability in all versions up to 2.0.2. This flaw allows authenticated users with Author-level access and higher to exploit the 'path' parameter in the 'get_content' AJAX action to include and execute arbitrary PHP files on the server. As a result, malicious actors could potentially bypass access controls, access sensitive information, or execute any PHP code contained within these files, leading to severe security breaches.
Affected Version(s)
RTMKit 0 <= 2.0.2