Impact
Unauthenticated Cross‑Site Scripting (XSS) vulnerability exists in the WordPress RTMKit plugin for versions up to 2.1.5. The flaw allows an attacker to inject arbitrary client‑side script code into web pages that visitors load without requiring authentication or a user session. The injected script can steal credentials, manipulate page content, or deliver malicious payloads to site visitors.
Affected Systems
The affected product is the RomeTheme RTMKit plugin used with WordPress installations. Versions 2.1.0 through 2.1.5, inclusive, are vulnerable. Any WordPress site that has installed these versions faces the stated risk until updated.
Risk and Exploitability
The CVSS base score of 7.1 reflects a moderate‑to‑high risk. No EPSS score is available, so the exact exploitation probability is uncertain, but the vulnerability is publicly reachable through unauthenticated XSS vectors. Because it is not listed in the CISA KEV catalog, there is no evidence of active exploitation yet; however, XSS attacks can be automated and produce significant damage to confidentiality, integrity, and availability.
OpenCVE Enrichment