Impact
The CVE-2026-62133 vulnerability is a Cross Site Request Forgery flaw in the WordPress RTMKit plugin versions up to 2.1.5. It allows an attacker to induce an authenticated user to submit requests that perform unauthorized actions within the plugin, potentially compromising the integrity of the site. The weakness is identified as CWE-352.
Affected Systems
WordPress sites that run the RTMKit plugin from the rometheme vendor, specifically any installation using version 2.1.5 or earlier.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk. The EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web browser while the user is authenticated to the site, with the attacker delivering malicious content that triggers an unintended request. The exploitation requires no special privileges beyond a user’s normal access to the site.
OpenCVE Enrichment