Impact
The Rometheme RTMKit plugin suffers from a stored cross‑site scripting flaw caused by improper neutralization of user‑controlled input when it is rendered into web pages. This weakness allows an attacker to inject malicious scripts that persist across sessions and are executed in the browsers of users who view the affected content. The exploitation can lead to theft of credentials, session hijacking, or defacement of the site, affecting the confidentiality and integrity of user data. The vulnerability is identified as CWE‑79.
Affected Systems
Any WordPress installation using the Rometheme RTMKit plugin version 1.6.0 or earlier is vulnerable. The affected products are Rometheme:RTMKit, and the issue applies to all releases from the initial version through the listed maximum version of 1.6.0.
Risk and Exploitability
This issue carries a CVSS score of 6.5, indicating moderate severity. The EPSS score is less than 1%, suggesting that the exploitation probability is low at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the injection of malicious payloads through input fields that are stored and later rendered on the page; an attacker can target any user who subsequently loads a page containing the compromised data.
OpenCVE Enrichment
EUVD