CVE-2026-5137 | rometheme RTMKit Plugin up to 2.0.7 on WordPress AJAX Endpoint _templates.php template filename control
A vulnerability marked as problematic has been reported in rometheme RTMKit Plugin up to 2.0.7 on WordPress. Affected by this vulnerability is an unknown functionality of the file _templates.php of the component AJAX Endpoint. The manipulation of the argument template leads to improper control of filename for include/require statement in php program (‘php remote file inclusion’).
This vulnerability is traded as CVE-2026-5137. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More