Title: Plugin vulnerability Broken Access control
Last modified: August 28, 2026

---

# Plugin vulnerability Broken Access control

 *  [imokweb](https://wordpress.org/support/users/imokweb/)
 * (@imokweb)
 * [1 week, 2 days ago](https://wordpress.org/support/topic/plugin-vulnerability-broken-access-control/)
 * Hi there
 * I received a notification from patchstack that this plugin has a vulnerability
   Could you investigate?
 * [https://patchstack.com/database/wordpress/plugin/romethemeform/vulnerability/wordpress-romethemeform-for-elementor-plugin-1-2-6-broken-access-control-vulnerability](https://patchstack.com/database/wordpress/plugin/romethemeform/vulnerability/wordpress-romethemeform-for-elementor-plugin-1-2-6-broken-access-control-vulnerability)
 * thanks

Viewing 1 replies (of 1 total)

 *  [nonchiedercilaparola](https://wordpress.org/support/users/nonchiedercilaparola/)
 * (@nonchiedercilaparola)
 * [1 week, 2 days ago](https://wordpress.org/support/topic/plugin-vulnerability-broken-access-control/#post-19005744)
 * hi same issue from wpmudev defender
 * > CVSS Score 4.3
   >  4.3 WordPress RomethemeForm For Elementor plugin <= 1.2.6 – Broken Access 
   > Control vulnerability
   > Vulnerability type: Broken Access ControlNo Update Available

Viewing 1 replies (of 1 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fplugin-vulnerability-broken-access-control%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/romethemeform/assets/icon-128x128.png?rev=3367512)
 * [RTMForm Builder](https://wordpress.org/plugins/romethemeform/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/romethemeform/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/romethemeform/)
 * [Active Topics](https://wordpress.org/support/plugin/romethemeform/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/romethemeform/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/romethemeform/reviews/)

 * 2 replies
 * 2 participants
 * Last reply from: [nonchiedercilaparola](https://wordpress.org/support/users/nonchiedercilaparola/)
 * Last activity: [1 week, 2 days ago](https://wordpress.org/support/topic/plugin-vulnerability-broken-access-control/#post-19005744)
 * Status: not resolved