CVE-2026-12906 LOW

The RTMKit WordPress plugin before 2
Generated: 10 Oct 2026 20:04 • CVE Threat Intelligence

Description

The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private, draft, pending, scheduled and trashed posts.

2.7
CVSS LOW

Details

Published
16 Jul 2026 07:16
Modified
16 Jul 2026 18:16
Source
CIRCL

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

References