CVE-2025-64283
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-64283 is an Insecure Direct Object Reference (IDOR) vulnerability in the RTMKit (rometheme-for-elementor) WordPress plugin by Rometheme, classified as an Authorization Bypass Through User-Controlled Key (CWE-639). It affects all versions of the plugin up to and including 1.6.7. The vulnerability was reported by Chazz Wolcott of Patchstack on January 15, 2025, published on February 14, 2025, and assigned a CVE on October 29, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).

Technical details

The vulnerability is rooted in improper access control enforcement within the RTMKit plugin, where object references (such as resource IDs) supplied by the user are not adequately validated against the authenticated user's authorization level (CWE-639). This allows a low-privileged authenticated user (Contributor role or higher) to manipulate object identifiers in requests to access resources or data they should not be permitted to view. The flaw is classified under OWASP Top 10 A7: Identification and Authentication Failures and is exploitable over the network without user interaction (Patchstack).

Impact

Successful exploitation allows an authenticated attacker with at least Contributor-level privileges to bypass authorization controls and access sensitive data or resources belonging to other users or restricted areas of the WordPress site. The impact is limited to confidentiality — there is no integrity or availability impact — but unauthorized access to sensitive files, database content, or private post data could expose personally identifiable information or site configuration details. The vulnerability does not enable remote code execution or privilege escalation on its own (Patchstack).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term. Patchstack classifies this as low priority with no impactful threat currently observed. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that IDOR-class vulnerabilities are sometimes leveraged in mass-exploit campaigns targeting WordPress plugins at scale (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the RTMKit (rometheme-for-elementor) plugin version 1.6.7 or earlier using tools like WPScan or by inspecting plugin directories.
  2. Obtain low-privileged access: Register or obtain a Contributor-level (or higher) account on the target WordPress site.
  3. Identify object references: Interact with plugin functionality to observe object identifiers (e.g., post IDs, form IDs, or resource keys) returned in HTTP responses or embedded in page source.
  4. Manipulate object references: Craft HTTP requests substituting the observed identifiers with those belonging to other users or restricted resources (e.g., incrementing or enumerating IDs).
  5. Access unauthorized data: Submit the manipulated requests and observe whether the plugin returns data or resources that should be restricted, achieving unauthorized information disclosure (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated requests (with valid session cookies) to RTMKit plugin endpoints with sequentially enumerated or out-of-range object IDs (e.g., ?id=1, ?id=2, etc.) from a single user account.
  • Logs: Repeated HTTP 200 responses to plugin API or AJAX endpoints (/wp-admin/admin-ajax.php) with varying object reference parameters from a low-privileged user.
  • Network: Unusual volume of requests to RTMKit-specific endpoints from a single authenticated session, potentially indicating automated enumeration of object IDs.

Mitigation and workarounds

The vulnerability is patched in RTMKit version 1.6.8. Site administrators should update the plugin to version 1.6.8 or later immediately via the WordPress plugin dashboard. If an immediate update is not possible, consider temporarily deactivating the plugin or restricting Contributor-level registrations until the patch can be applied. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-81648CRITICAL10
  • cryptopayment-gateway
NoNoSep 13, 2026
CVE-2026-88793HIGH8.8
  • youram-youtube-embed
NoNoSep 13, 2026
CVE-2026-85129HIGH8.8
  • hoo-companion
NoNoSep 13, 2026
CVE-2026-88802HIGH7.5
  • mobile-events-manager
NoYesSep 13, 2026
CVE-2026-89050MEDIUM4.3
  • quick-adsense-reloaded
NoYesSep 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management