CVE-2025-30911: WordPress RomethemeKit For Elementor plugin <= 1.5.4 - Arbitrary Plugin Installation/Activation to RCE vulnerability
Published Apr 1, 2025
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This issue affects RTMKit: from n/a through <= 1.5.4.
Affected Software
1 affected component
Rometheme RomethemeKit For Elementor<=1.5.4
Remediation
Information
Update the WordPress RomethemeKit For Elementor plugin to the latest available version (at least 1.5.5).
Event History
Apr 1, 2025
CVE Published
via MITRE·05:31 AM
Data Sourced
via MITRE·05:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-30911?
CVE-2025-30911 is considered a critical vulnerability due to its potential for command injection.
2
How do I fix CVE-2025-30911?
To mitigate CVE-2025-30911, update RomethemeKit For Elementor to version 1.5.5 or later.
3
What versions of RomethemeKit For Elementor are affected by CVE-2025-30911?
CVE-2025-30911 affects all versions of RomethemeKit For Elementor from n/a to 1.5.4.
4
What type of vulnerability is CVE-2025-30911?
CVE-2025-30911 is classified as a 'Code Injection' vulnerability allowing command execution.
5
Who is the vendor associated with CVE-2025-30911?
The vendor associated with CVE-2025-30911 is Rometheme, the developer of RomethemeKit For Elementor.