CVE-2026-84752
—PHP Object Injection (CWE-502) in RTMKit WordPress Plugin Through 2.1.5
CVE-2026-84752 is a PHP object injection flaw (CWE-502, deserialization of untrusted data) in the RTMKit WordPress plugin, affecting all versions through 2.1.5. A user with Contributor-level privileges (a low-privilege authenticated role) can trigger the vulnerability by getting the plugin to deserialize attacker-controlled data, per the CVSS vector (AV:N/AC:L/PR:L/UI:N). Successful exploitation carries high potential impact to confidentiality, integrity, and availability, which in PHP object injection typically means attacker-controlled object property manipulation that can lead to data exposure, file operations, or arbitrary code execution via available gadget chains. Any WordPress site running RTMKit 2.1.5 or earlier is affected. There is currently no public proof of concept, no known in-the-wild exploitation, and the EPSS probability of exploitation within 30 days is low at 0.3% (21st percentile).
What to do: Update the RTMKit plugin to the latest available release as soon as a patched version beyond 2.1.5 is published, and check the plugin's changelog or the vendor/Patchstack advisory for the fixed version number. Until patched, consider deactivating the plugin or limiting Contributor-role accounts on sites running RTMKit, and review contributor submissions and plugin logs for signs of serialized payload tampering.
| RTMKit WordPress plugin | <= 2.1.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.