PatchSiren

rometheme CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM rometheme CVE published 2026-09-11

CVE-2026-62133

A Cross Site Request Forgery (CSRF) vulnerability exists in RTMKit versions up to 2.1.5. This issue allows attackers to perform unintended actions on behalf of users. Defenders should assess exposure, particularly in systems using RTMKit. The vulnerability has a CVSS score of 5.4 and is considered medium severity.

MEDIUM rometheme CVE published 2026-06-16

CVE-2026-5149

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7. This is due to the get_submission_content AJAX endpoint lacking a capability check to verify that a user has permission to access the requested form submission data. This makes it possible for authenticated attackers, with Contributor-level access and above, to view arbitrary form submissi [truncated]