Information leakage vulnerability in RomethemeKit For Elementor 1.5.2

The RomethemeKit For Elementor plugin for WordPress is at risk of exposing sensitive information. This can happen in all versions up to 1.5.2, through the register_controls function in widgets/offcanvas-rometheme.php. This could allow attackers with Contributor-level access or higher to access private, pending, and draft template data.

Detected in:

RTMKit fixed vulnerable versions:
RTMKit Addons for Elementor fixed vulnerable versions: >= * <= 1.5.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.