Junglewise Threat Intelligence

CVE-2026-39711: stmcan RT-Theme 18 Extensions Sensitive Data Exposure

CVE-2026-39711 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Technologies: Stmcan RT-Theme 18 Extensions. Vendors: Stmcan.

Executive brief

The RT-Theme 18 | Extensions plugin for WordPress contains a vulnerability that allows sensitive information to be leaked to unauthorized users. This plugin is typically used to extend the functionality of the RT-Theme 18 website template. An attacker could exploit this to view internal data that is not intended for public access, potentially aiding in further attacks against the website.

Technical details

A sensitive data exposure vulnerability (CWE-201) exists in the stmcan RT-Theme 18 | Extensions (rt18-extensions) plugin for WordPress. The flaw occurs due to the improper insertion of sensitive information into data sent by the application, which allows unauthenticated remote attackers to retrieve embedded sensitive data. The attack can be performed over the network without any user interaction. As of the advisory date, no official patch has been released for versions up to and including 2.5.

Affected products

  • stmcan RT-Theme 18 | Extensions (rt18-extensions) <= 2.5

Timeline

  • 2026-01-31: other: Vulnerability reported by researcher Bonds
  • 2026-03-02: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD

References

Related threats