WordPress RTMKit plugin <= 1.6.5 - Arbitrary File Upload vulnerability
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.9epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
In short
The RTMKit WordPress plugin allows attackers to upload malicious files without proper restrictions, potentially letting them take control of the website. This vulnerability affects versions up to 1.6.5.
Technical detail
CWE-434 unrestricted file upload vulnerability in RTMKit <= 1.6.5 allows unauthenticated or low-privileged attackers to upload arbitrary files with dangerous types, potentially leading to remote code execution or website compromise. The plugin fails to implement proper file type validation and restrictions on upload functionality.
Summary generated and translated by AI from the official description.
Unrestricted Upload of File with Dangerous Type vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue affects RTMKit: from n/a through <= 1.6.5.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
Rometheme · RTMKit