Impact
The WordPress RTMKit plugin versions up to 2.1.5 contain an unauthenticated Cross‑Site Scripting flaw. The vulnerability allows an attacker to inject arbitrary script code into pages served to visitors, thereby enabling client‑side code execution when users load the affected pages. The description does not specify exact payloads; however, the typical consequences of an XSS flaw—such as leaking session cookies, hijacking user accounts, or redirecting visitors to malicious sites—are inferred from common XSS attack patterns.
Affected Systems
The RomeTheme RTMKit plugin used with WordPress installations, specifically versions 2.1.0 through 2.1.5, is affected. Any WordPress site that still hosts one of these versions remains vulnerable until the plugin is upgraded.
Risk and Exploitability
The CVSS base score of 7.1 indicates a moderate‑to‑high risk. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation yet, but the flaw is publicly reachable via unauthenticated XSS vectors. Attackers could embed malicious scripts via plugin input fields or crafted URLs, which would then execute in the browsers of all site visitors. Due to its lack of authentication requirement, the attack surface is significant, making it a practical target for automated exploitation.
OpenCVE Enrichment