ZeroHour

CVE-2026-84752

PHP Object Injection (CWE-502) in RTMKit WordPress Plugin Through 2.1.5

CVSS 3.1
8.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-84752 is a PHP object injection flaw (CWE-502, deserialization of untrusted data) in the RTMKit WordPress plugin, affecting all versions through 2.1.5. A user with Contributor-level privileges (a low-privilege authenticated role) can trigger the vulnerability by getting the plugin to deserialize attacker-controlled data, per the CVSS vector (AV:N/AC:L/PR:L/UI:N). Successful exploitation carries high potential impact to confidentiality, integrity, and availability, which in PHP object injection typically means attacker-controlled object property manipulation that can lead to data exposure, file operations, or arbitrary code execution via available gadget chains. Any WordPress site running RTMKit 2.1.5 or earlier is affected. There is currently no public proof of concept, no known in-the-wild exploitation, and the EPSS probability of exploitation within 30 days is low at 0.3% (21st percentile).

What to do: Update the RTMKit plugin to the latest available release as soon as a patched version beyond 2.1.5 is published, and check the plugin's changelog or the vendor/Patchstack advisory for the fixed version number. Until patched, consider deactivating the plugin or limiting Contributor-role accounts on sites running RTMKit, and review contributor submissions and plugin logs for signs of serialized payload tampering.

Affected
RTMKit WordPress plugin<= 2.1.5
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.

Ecosystems
WordPress
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.