SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-12907

LOW · CVSS 2.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The RTMKit WordPress plugin prior to version 2.0.9 is vulnerable due to insufficient capability checks, enabling users with Author roles to create and activate site-wide templates that can alter global elements like headers and footers. This could lead to unauthorized modifications affecting all visitors, potentially compromising the site's integrity. WordPress site administrators and security teams should prioritize this vulnerability to prevent misuse by lower-privileged users.

CVE
CVE-2026-12907
Severity
LOW
CVSS
2.7
EPSS
0.17%
WordPress

Original NVD Description

The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to create and activate a site-wide template that overrides the header, footer or other global areas displayed to all visitors, which is normally restricted to administrators.