Description
Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.
Published: 2026-09-03
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Cross‑Site Scripting (XSS) vulnerability exists in the WordPress RTMKit plugin for versions up to 2.1.5. The flaw allows an attacker to inject arbitrary client‑side script code into web pages that visitors load without requiring authentication or a user session. The injected script can steal credentials, manipulate page content, or deliver malicious payloads to site visitors.

Affected Systems

The affected product is the RomeTheme RTMKit plugin used with WordPress installations. Versions 2.1.0 through 2.1.5, inclusive, are vulnerable. Any WordPress site that has installed these versions faces the stated risk until updated.

Risk and Exploitability

The CVSS base score of 7.1 reflects a moderate‑to‑high risk. No EPSS score is available, so the exact exploitation probability is uncertain, but the vulnerability is publicly reachable through unauthenticated XSS vectors. Because it is not listed in the CISA KEV catalog, there is no evidence of active exploitation yet; however, XSS attacks can be automated and produce significant damage to confidentiality, integrity, and availability.

Generated by OpenCVE AI on September 3, 2026 at 17:24 UTC.

Remediation

Vendor Solution

Update the WordPress RTMKit Plugin to the latest available version (at least 2.1.6).


OpenCVE Recommended Actions

  • Update the WordPress RTMKit Plugin to version 2.1.6 or later.
  • If an update cannot be performed immediately, disable or uninstall the RTMKit plugin to remove the vulnerable code from the site.
  • Enforce a strict Content Security Policy and ensure that any user input processed by the plugin is properly escaped or sanitized to prevent script injection.

Generated by OpenCVE AI on September 3, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.
Title WordPress RTMKit plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-03T16:31:48.809Z

Reserved: 2026-09-02T09:57:42.761Z

Link: CVE-2026-84763

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:27.450

Modified: 2026-09-03T17:25:25.113

Link: CVE-2026-84763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T17:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')