CVE-2025-62065: WordPress RTMKit plugin <= 1.6.5 - Arbitrary File Upload vulnerability
Published Nov 6, 2025
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue affects RTMKit: from n/a through <= 1.6.5.
Affected Software
2 affected components
Rometheme RTMKit<=1.6.5
WordPress RTMKit<=1.6.5
Event History
Nov 6, 2025
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62065?
CVE-2025-62065 is considered a high severity vulnerability due to the potential for an attacker to upload malicious files.
2
How do I fix CVE-2025-62065?
To mitigate CVE-2025-62065, update Rometheme RTMKit to the latest version beyond 1.6.5.
3
What type of vulnerability is CVE-2025-62065?
CVE-2025-62065 is classified as an Unrestricted Upload of File with Dangerous Type vulnerability.
4
Which versions of Rometheme RTMKit are affected by CVE-2025-62065?
CVE-2025-62065 affects Rometheme RTMKit versions from n/a to 1.6.5 inclusive.
5
Can CVE-2025-62065 be exploited remotely?
Yes, CVE-2025-62065 can be exploited remotely, allowing attackers to upload harmful files directly.