ZeroHour

CVE-2026-84763

Unauthenticated Cross-Site Scripting (XSS) in RTMKit 2.1.5 and earlier

CVSS 3.1
7.1 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-84763 is an unauthenticated cross-site scripting flaw (CWE-79) in RTMKit that affects all versions up to and including 2.1.5. Because it requires no credentials, an attacker can craft malicious input — typically a link or request parameter containing script content — that the vulnerable software processes and renders without proper sanitization; the CVSS 'user interaction' requirement means the victim must load the attacker-crafted content (for example by clicking a link). If successful, the attacker executes arbitrary JavaScript in the victim's browser in the context of the affected application, enabling session cookie theft, redirection, phishing content injection, or actions performed on the user's behalf; the 'changed' scope in the CVSS vector reflects the script escaping the component's context into the broader application origin. Anyone running RTMKit 2.1.5 or earlier is affected, though the size of that install base is unknown from the available data. There is currently no public proof-of-concept, the issue is not in CISA's KEV, and EPSS estimates only a 0.1% probability of exploitation within 30 days (4th percentile), so no known active exploitation is occurring.

What to do: Upgrade RTMKit to the first release newer than 2.1.5 (check the vendor's advisory or changelog for the exact fixed version) on any deployment running 2.1.5 or earlier. Until patched, consider disabling or restricting the component and remind users not to click untrusted links pointing at affected deployments, since exploitation requires user interaction. Given the absence of a public PoC, KEV listing, and low EPSS score, this can be prioritized below actively exploited flaws, but should still be scheduled for remediation.

Affected
RTMKit<= 2.1.5
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.