Junglewise Threat Intelligence

CVE-2026-57743: stmcan RT-Theme 18 Extensions local file inclusion

CVE-2026-57743 · Severity: high · CVSS 8.1 · Published 2026-07-13

Technologies: Stmcan RT-Theme 18 Extensions. Vendors: Stmcan.

Executive brief

A security vulnerability exists in the RT-Theme 18 Extensions plugin for WordPress, which is used to add functionality to websites using the RT-Theme 18 template. An attacker can exploit this flaw to view sensitive internal files on the web server, such as configuration files containing database passwords. This could lead to a full compromise of the website's data and underlying server.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the stmcan RT-Theme 18 | Extensions (rt18-extensions) plugin for WordPress through version 2.5. The flaw stems from improper validation of user-supplied input used in PHP include or require statements (CWE-98). An unauthenticated remote attacker can exploit this by submitting specially crafted requests to include and execute local files on the server. Successful exploitation could allow the attacker to read sensitive files (like wp-config.php) or potentially achieve remote code execution if they can upload or influence the contents of a local file. As of the advisory date, no official patch is available.

Affected products

  • stmcan RT-Theme 18 | Extensions (rt18-extensions) <= 2.5

Timeline

  • 2026-01-31: disclosed: Reported by Bonds to Patchstack
  • 2026-07-06: advisory: Patchstack published advisory and mitigation rules
  • 2026-07-13: advisory: CVE published to NVD dataset

References

Related threats