CVE-2025-30911: Rometheme Rtmkit

Critical severity, CVSS 9.9. EPSS: 1.9% chance of exploitation in the next 30 days.

Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This issue affects RTMKit: from n/a through <= 1.5.4.

Affected products

Published 2025-04-01. Last modified 2026-06-17.