CVE-2026-74003

WordPress RomethemeForm For Elementor plugin <= 1.2.6 - Broken Access Control vulnerability

Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.


We have discovered 2,113 live websites that are affected by CVE-2026-74003.

Run a Free Instant Scan




Affected Software

Product  Romethemeform
Category Wordpress Plugins
Vulnerable Domains2,113 live websites (100% of Romethemeform install base)
Vulnerable Versions
  • from 0 through 1.2.6
Vulnerable Versions Count13 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 18, 2026
  • Updated - Aug 18, 2026

Credits

  • Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-74003
United States695 websites



Germany172 websites
Brazil139 websites
GB118 websites
Spain89 websites
India82 websites
Cyprus81 websites
France68 websites
Poland57 websites
Italy47 websites

Website Distribution by TLD

Number of websites using CVE-2026-74003
.com1,048 websites
.com.br135 websites
.org85 websites
.de71 websites
.co.uk59 websites
.net46 websites
.pl43 websites
.it39 websites
.fr34 websites
.es33 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-74003

Top websites that are affected by CVE-2026-74003. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******************.com United States***,***
******.info GB***,***
**********.de Germany***,***
****************.com United States***,***
**************.nl Netherlands***,***
****.org Kenya***,***
*****************.com United States***,***
*********.com United States***,***
*********.net ***,***
**********.com United States***,***
See full domain list

FAQ

CVE-2026-74003 is Missing Authorization in Romethemeform
A total of 2,113 websites have been identified as vulnerable to CVE-2026-74003, based on global website indexing conducted by WebTechSurvey.
The Romethemeform is affected by the CVE-2026-74003 vulnerability.
Romethemeform versions up to and including 1.2.6 are vulnerable to CVE-2026-74003.