Vulnerabilities > Rometheme

DATE CVE VULNERABILITY TITLE RISK
2025-03-08 CVE-2024-10326 Missing Authorization vulnerability in Rometheme Romethemekit for Elementor
The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_options and reset_widgets functions in all versions up to, and including, 1.5.3.
network
low complexity
rometheme CWE-862
4.3
2025-01-24 CVE-2024-10324 Unspecified vulnerability in Rometheme Romethemekit for Elementor
The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.2 via the register_controls function in widgets/offcanvas-rometheme.php.
network
low complexity
rometheme
4.3