Executive brief
The RT-Theme 18 Extensions plugin for WordPress is vulnerable to a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By enticing a logged-in user to click a malicious link or visit a specific webpage, an attacker could modify site settings or perform administrative tasks without the user's consent. This could lead to unauthorized changes to the website's configuration or content.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the stmcan RT-Theme 18 | Extensions (rt18-extensions) plugin for WordPress through version 2.5. The vulnerability is caused by a lack of proper nonce validation or equivalent CSRF protections on sensitive administrative functions. An unauthenticated remote attacker can exploit this by tricking a privileged user (such as an administrator) into visiting a malicious website or clicking a crafted link while authenticated to the WordPress site. Successful exploitation allows the attacker to execute unauthorized actions on behalf of the victim, potentially altering site configurations. As of the advisory date, no official patch has been released.
Affected products
- stmcan RT-Theme 18 | Extensions (rt18-extensions) <= 2.5
Timeline
- 2026-01-31: other: Vulnerability reported by researcher Bonds
- 2026-03-02: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE published to NVD