CVE-2026-84763: WordPress RTMKit plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress RTMKit pluginto a version that resolves this vulnerability.Fixed in 2.1.6
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or plugin privileges. Exploitation requires user interaction, as indicated by the UI:R vector.
Which installations should be treated as affected?
WordPress sites using RTMKit version 2.1.5 or earlier should be treated as affected based on the available information. The data does not state whether any particular plugin configuration prevents exploitation.
What impact can successful exploitation have?
Successful exploitation can affect confidentiality, integrity, and availability at a low level, and the impact scope can extend beyond the vulnerable component. The provided severity vector is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L.