Junglewise Threat Intelligence

CVE-2026-57745: stmcan RT-Theme 18 Extensions Reflected XSS

CVE-2026-57745 · Severity: high · CVSS 7.1 · Published 2026-07-13

Technologies: Stmcan RT-Theme 18 Extensions. Vendors: Stmcan.

Executive brief

The RT-Theme 18 | Extensions plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into web pages. This occurs when the plugin fails to properly clean user-provided data before displaying it back to visitors. If a site administrator or visitor clicks a specially crafted link, an attacker could steal login sessions, redirect users to malicious websites, or deface the site's content.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the stmcan RT-Theme 18 | Extensions (rt18-extensions) plugin for WordPress through version 2.5. The flaw stems from improper neutralization of user-supplied input during web page generation. An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized actions. As of the advisory date, no official patch has been released.

Affected products

  • stmcan RT-Theme 18 | Extensions (rt18-extensions) <= 2.5

Timeline

  • 2026-01-31: other: Vulnerability reported by researcher Bonds
  • 2026-07-06: advisory: Initial advisory published by Patchstack
  • 2026-07-13: disclosed: CVE published to NVD dataset

References

Related threats