The RomethemeForm For Elementor plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the export_entries, rtformnewform, and rtformupdate functions in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to export arbitrary form submissions, create new forms, or update any post title or certain metadata.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-58567 The RomethemeForm For Elementor plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the export_entries, rtformnewform, and rtformupdate functions in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to export arbitrary form submissions, create new forms, or update any post title or certain metadata.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 27 Feb 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Rometheme
Rometheme romethemeform For Elementor
CPEs cpe:2.3:a:rometheme:romethemeform_for_elementor:*:*:*:*:*:*:*:*
Vendors & Products Rometheme
Rometheme romethemeform For Elementor
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-02T08:28:21.144Z

Reserved: 2023-11-27T14:34:15.631Z

Link: CVE-2023-6325

cve-icon Vulnrichment

Updated: 2024-08-02T08:28:21.144Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-23T05:15:48.773

Modified: 2024-11-21T08:43:37.750

Link: CVE-2023-6325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.