Impact
A deserialization flaw in the stmcan RT‑Theme 18 | Extensions WordPress plugin allows an attacker to inject a crafted PHP object that the plugin deserializes and executes, enabling arbitrary code execution on the site. The vulnerability is classified as CWE‑502 and presents a high‑severity remote code execution risk, compromising confidentiality, integrity, and availability of the affected WordPress installation.
Affected Systems
The vulnerability affects any installation of the RT‑Theme 18 | Extensions plugin for WordPress running a version of 2.5 or earlier. The CNA indicates the affected range as from n/a through ≤ 2.5, meaning all releases prior to 2.6 are impacted.
Risk and Exploitability
The CVSS score of 9.8 when the flaw is exploitable. Despite an EPSS score of less than 1 %, indicating a low probability of exploitation, no KEV listing suggests no publicly known active exploits. The likely attack vector is a remote web request that delivers specially crafted data to the plugin’s deserialization logic; successful exploitation requires the input to be accepted and executed within the PHP runtime, giving the attacker control over the server.
OpenCVE Enrichment