CVE-2026-84752: WordPress RTMKit plugin <= 2.1.5 - PHP Object Injection vulnerability
Published Sep 3, 2026
·Updated
Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.
Affected Software
1 affected component
WordPress RTMKit plugin<=2.1.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress RTMKit pluginto a version that resolves this vulnerability.Fixed in 2.1.6
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated user with Contributor-level access can exploit it. The CVSS vector indicates network access, low attack complexity, and no user interaction are required.
2
What is the potential impact of successful exploitation?
Successful exploitation can affect confidentiality, integrity, and availability at a high level, according to the CVSS metrics.
3
How can I determine whether my site is affected?
A site is affected if it has the WordPress RTMKit plugin installed at version 2.1.5 or an earlier version.