Executive brief
The RT-Theme 18 Extensions plugin for WordPress is vulnerable to a critical security flaw that allows attackers to inject malicious objects into the website's memory. This could lead to complete site takeover, unauthorized data access, or the deletion of critical files. Because this can be exploited remotely without any login credentials, it poses a significant risk to business operations and data integrity.
Technical details
A Deserialization of Untrusted Data vulnerability (CWE-502) exists in the stmcan RT-Theme 18 | Extensions (rt18-extensions) plugin through version 2.5. The flaw allows for PHP Object Injection when the application processes specially crafted input without proper validation. An unauthenticated remote attacker can exploit this to inject arbitrary PHP objects, which, if a suitable POP (Property Oriented Programming) chain is present in the environment, can lead to remote code execution, file manipulation, or database compromise. As of the advisory date, no official patch has been released by the vendor.
Affected products
- stmcan RT-Theme 18 | Extensions (rt18-extensions) <= 2.5
Timeline
- 2026-01-31: disclosed: Reported by Bonds to Patchstack
- 2026-07-06: advisory: Patchstack published the vulnerability details
- 2026-07-13: advisory: CVE published to NVD dataset