CVE-2026-62133: WordPress RTMKit plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability
Published Sep 11, 2026
·Updated
Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.
Affected Software
1 affected component
WordPress/RTMKit<=2.1.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress RTMKit pluginto a version that resolves this vulnerability.Fixed in 2.1.6
Event History
Sep 11, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
WordPress sites using the RTMKit plugin version 2.1.5 or earlier are affected.
2
What does an attacker need to exploit this issue?
The vulnerability is network-accessible, requires no attacker privileges, and requires user interaction. The description identifies the affected user context as a subscriber.
3
What security impact can exploitation have?
Successful exploitation may affect integrity and availability. No confidentiality impact is indicated by the supplied severity vector.