Executive brief
RTMKit is a WordPress plugin that provides theme components for the Elementor page builder. A PHP object injection vulnerability in versions up to 2.1.5 allows users with contributor-level permissions to execute arbitrary actions on the server, potentially leading to unauthorized data modification, code execution, or site compromise.
Technical details
The vulnerability is a PHP Object Injection (CWE-502) in RTMKit plugin versions <= 2.1.5. It requires contributor-level privileges to exploit, meaning an attacker must have an active WordPress account with at least contributor permissions. The flaw allows manipulation of how the server processes serialized data objects, enabling remote code execution or other malicious server-side actions. The vulnerability was patched in version 2.1.6, which should be deployed immediately.
Affected products
- Rometheme RTMKit <=2.1.5
Timeline
- 2026-09-03: disclosed: CVE-2026-84752 published
- 2026-09-02: patched: Version 2.1.6 released with fix