ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-12906

LOW Export PDF

The RTMKit WordPress plugin before 2

The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private, draft, pending, scheduled and trashed posts.

CVSS Score
2.7
LOW
Published
16 Jul 2026 07:16
Modified
16 Jul 2026 18:16
Source
CIRCL

CVSS v3 Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Complexity
Low
Privileges
High
Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Weaknesses (CWE)

CWE-639

Affected Systems

No vendor data available.

KEV Status

Not in CISA KEV catalog