WordPress Plugin Vulnerabilities

RTMKit < 2.0.8 - Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter

Description

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submission_content AJAX endpoint lacking a capability check to verify that a user has permission to access the requested form submission data. This makes it possible for authenticated attackers, with Contributor-level access and above, to view arbitrary form submissions from other users by iterating the entries_id parameter.

Affects Plugins

References

Classification

Type
INCORRECT AUTHORISATION
CWE

Miscellaneous

Original Researcher
wesley (wcraft)
Verified
No

Timeline

Publicly Published
2026-06-15 (about 3 months ago)
Added
2026-06-15 (about 3 months ago)
Last Updated
2026-06-16 (about 3 months ago)

Other