Junglewise Threat Intelligence

CVE-2026-84763: RTMKit cross-site scripting (XSS) vulnerability

CVE-2026-84763 · Severity: high · CVSS 7.1 · Published 2026-09-03

Technologies: RomeTheme RTMKit. Vendors: RomeTheme.

Executive brief

RTMKit is a WordPress plugin for Elementor that enables page building and design features. The plugin contains an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into websites. Exploited successfully, this could lead to theft of visitor data, account hijacking, or malicious redirects affecting thousands of sites simultaneously.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw in RTMKit versions 2.1.5 and earlier that requires no authentication to trigger. The attack involves injecting malicious JavaScript that executes in the context of affected web pages when visited by users. While user interaction is required (e.g., clicking a link or visiting a crafted page), the lack of authentication requirement makes this a network-accessible threat. Attackers can harvest session tokens, redirect visitors to phishing sites, or perform actions on behalf of logged-in users. The vulnerability has been patched in version 2.1.6.

Affected products

  • Rometheme RTMKit <=2.1.5

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: version 2.1.6 released

References

Related threats