Junglewise Threat Intelligence

CVE-2026-62133: RTMKit Cross-Site Request Forgery in subscriber actions

CVE-2026-62133 · Severity: medium · CVSS 5.4 · Published 2026-09-11

Technologies: RomeTheme RTMKit. Vendors: RomeTheme.

Executive brief

RTMKit is a WordPress plugin for Elementor website building. A cross-site request forgery (CSRF) vulnerability in versions up to 2.1.5 allows attackers to trick logged-in subscribers into performing unintended actions, such as changing settings or submitting forms, without their knowledge or consent. This could lead to unauthorized account modifications or data changes on affected WordPress sites.

Technical details

The vulnerability is a cross-site request forgery (CSRF) flaw in RTMKit versions <= 2.1.5 that affects subscribers. CSRF attacks exploit the trust a web application places in authenticated user requests by injecting malicious requests into pages the user visits. Successful exploitation requires a subscriber-level user to interact with a crafted malicious link or page. An attacker can trick the user into performing unintended actions within the plugin without their explicit consent. The vulnerability has been patched in version 2.1.6 and later.

Affected products

  • Rometheme RTMKit <= 2.1.5

Timeline

  • 2026-08-29: disclosed: Reported by MYUNGYONG LEE
  • 2026-09-10: advisory: Published by Patchstack
  • 2026-09-10: patched: Version 2.1.6 released with fix

References

Related threats