Pricing
Case studies
Login
Start trial
RTMKit
Rometheme
Developer
2.0.6
Latest version
50,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
12 patched
4 Mitigation rules
Reflected Cross-Site Scripting via 'themebuilder' Parameter vulnerability
<= 1.6.8
11/03/2026
Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates vulnerability
<= 1.5.2
31/12/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Repeater Block Attribute vulnerability
<= 1.6.5
17/11/2025
Arbitrary File Upload vulnerability
<= 1.6.5
18/10/2025
Cross Site Scripting (XSS) vulnerability
<= 1.6.0
05/06/2025
Arbitrary Plugin Installation/Activation to RCE vulnerability
<= 1.5.4
27/03/2025
Missing Authorization in save_options and reset_widgets vulnerability
<= 1.5.3
08/03/2025
Insecure Direct Object References (IDOR) vulnerability
<= 1.6.7
14/02/2025
Broken Access Control vulnerability
<= 1.5.2
24/01/2025
Cross Site Scripting (XSS) vulnerability
<= 1.5.0
30/09/2024
Broken Access Control vulnerability
<= 1.4.1
29/04/2024
Cross Site Scripting (XSS) vulnerability
<= 1.4.1
22/04/2024