Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 16 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rometheme
Rometheme rtmkit Wordpress Wordpress wordpress |
|
| Vendors & Products |
Rometheme
Rometheme rtmkit Wordpress Wordpress wordpress |
Tue, 16 Jun 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submission_content AJAX endpoint lacking a capability check to verify that a user has permission to access the requested form submission data. This makes it possible for authenticated attackers, with Contributor-level access and above, to view arbitrary form submissions from other users by iterating the entries_id parameter. | |
| Title | RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-06-16T16:06:14.076Z
Reserved: 2026-03-30T13:24:38.966Z
Link: CVE-2026-5149
Updated: 2026-06-16T16:06:09.751Z
Status : Deferred
Published: 2026-06-16T06:16:58.337
Modified: 2026-06-16T15:22:49.577
Link: CVE-2026-5149
No data.
OpenCVE Enrichment
Updated: 2026-06-18T00:30:14Z