CyberRota Analysis
AI-GeneratedThe RTMKit WordPress plugin prior to version 2.0.9 lacks proper capability checks in its AJAX actions, enabling users with Contributor roles to access and read the titles of private, draft, pending, scheduled, and trashed posts belonging to other users. This vulnerability poses a risk to user privacy and content confidentiality within WordPress sites. WordPress administrators and site owners should prioritize updating the plugin to mitigate potential information exposure.
Original NVD Description
The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private, draft, pending, scheduled and trashed posts.