
Cloud Vulnerability DB
A community-led vulnerabilities database
The RomethemeForm For Elementor plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the export_entries, rtformnewform, and rtformupdate functions in all versions up to, and including, 1.1.5. This vulnerability was disclosed on May 22, 2024 (Wordfence).
The vulnerability stems from missing capability checks in three key functions: export_entries, rtformnewform, and rtformupdate. This security flaw has been assigned a CVSS v3.1 base score of 5.3 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (NVD).
The vulnerability allows unauthenticated attackers to export arbitrary form submissions, create new forms, or update any post title or certain metadata. This poses a significant risk to data confidentiality and system integrity (NVD).
The vulnerability is exploitable by unauthenticated attackers and requires no user interaction. The attack complexity is low, making it relatively straightforward to exploit (Wordfence).
Users should immediately update their RomethemeForm For Elementor plugin to a version newer than 1.1.5 if available. The vulnerability has been fixed in subsequent releases (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."