Rometheme develops WordPress plugins focused on page-building and design tools, with the Romethemekit for Elementor representing its primary affected product. The observed vulnerability pattern centers on information-disclosure and authorization weaknesses characteristic of web application plugins operating within the WordPress ecosystem, where metadata exposure and access-control gaps recur across this class of builder extensions. Current vulnerability counts, severity, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rometheme over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-33919MEDIUM Missing Authorization vulnerability in Rometheme RomethemeKit For Elementor.This issue affects RomethemeKit For Elementor: from n/a through 1.4.1. | May 3, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-10326MEDIUM The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_options and reset_widgets funct | Mar 8, 2025 | 4.3 | 16 | NO | NO |
CVE-2024-10324MEDIUM The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.2 via the register_controls function i | Jan 24, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rometheme.
Media articles that mention a CVE ID that affects a product developed by Rometheme — matched by CVE ID, not by vendor name.