Description
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
Published: 2026-07-13
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A deserialization flaw in the stmcan RT‑Theme 18 | Extensions WordPress plugin allows an attacker to inject a crafted PHP object that the plugin deserializes and executes, enabling arbitrary code execution on the site. The vulnerability is classified as CWE‑502 and presents a high‑severity remote code execution risk, compromising confidentiality, integrity, and availability of the affected WordPress installation.

Affected Systems

The vulnerability affects any installation of the RT‑Theme 18 | Extensions plugin for WordPress running a version of 2.5 or earlier. The CNA indicates the affected range as from n/a through ≤ 2.5, meaning all releases prior to 2.6 are impacted.

Risk and Exploitability

The CVSS score of 9.8 when the flaw is exploitable. Despite an EPSS score of less than 1 %, indicating a low probability of exploitation, no KEV listing suggests no publicly known active exploits. The likely attack vector is a remote web request that delivers specially crafted data to the plugin’s deserialization logic; successful exploitation requires the input to be accepted and executed within the PHP runtime, giving the attacker control over the server.

Generated by OpenCVE AI on August 1, 2026 at 10:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RT‑Theme 18 | Extensions to the latest release newer than version 2.5, which removes the vulnerable deserialization logic.
  • If an immediate upgrade is not possible, temporarily deactivate or uninstall the plugin to eliminate the attack surface.
  • Configure the application or web server to block or sanitize data handled by the plugin, ensuring that PHP object deserialization is disallowed for untrusted sources.

Generated by OpenCVE AI on August 1, 2026 at 10:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Stmcan
Stmcan rt-theme 18 | Extensions
Wordpress
Wordpress wordpress
Vendors & Products Stmcan
Stmcan rt-theme 18 | Extensions
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
Title WordPress RT-Theme 18 | Extensions plugin <= 2.5 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Stmcan Rt-theme 18 | Extensions
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:27:11.053Z

Reserved: 2026-06-25T08:04:29.579Z

Link: CVE-2026-57744

cve-icon Vulnrichment

Updated: 2026-07-13T13:27:08.101Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data