The RTMKit WordPress plugin before 2
The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private, draft, pending, scheduled and trashed posts.
CVSS Score
2.7
LOW
Published
16 Jul 2026 07:16
Modified
16 Jul 2026 18:16
Source
CIRCL
CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Complexity
Low
Privileges
High
Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Weaknesses (CWE)
CWE-639
Affected Systems
No vendor data available.
External Links
KEV Status
Not in CISA KEV catalog