CVE-2026-62133
Received Received - Intake

Subscriber CSRF in RTMKit <= 2.1.5

Vulnerability report for CVE-2026-62133, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: Patchstack

Description

Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
patchstack rtmkit to 2.1.5 (inc)
rometheme rtmkit to 2.1.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-62133 is a Cross Site Request Forgery (CSRF) vulnerability in the RTMKit WordPress plugin versions 2.1.5 and below. It allows attackers to trick authenticated users into executing unwanted actions by leveraging their active session. The vulnerability requires user interaction, such as clicking a malicious link.

Detection Guidance

Detection involves checking the installed version of the RTMKit plugin. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin directory for version details. Look for versions 2.1.5 or below.

Impact Analysis

This vulnerability could allow attackers to perform actions on behalf of higher privileged users without their consent. For example, it might enable unauthorized changes to plugin settings or content. The impact is limited due to the need for user interaction and the low CVSS score.

Compliance Impact

This CSRF vulnerability could potentially lead to unauthorized actions being performed by authenticated users, which may result in data breaches or unauthorized modifications. Such incidents could violate compliance requirements under GDPR (data protection) or HIPAA (healthcare data security) if sensitive user or patient data is exposed or altered without authorization.

Mitigation Strategies

Immediately update the RTMKit plugin to version 2.1.6 or later. If updating is not possible, contact your hosting provider or web developer for assistance. Enable auto-updates if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62133. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart