VYPR
Medium severity5.4NVD Advisory· Published Apr 8, 2026· Updated Apr 24, 2026

CVE-2026-39710

CVE-2026-39710

Description

Cross-Site Request Forgery (CSRF) vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Cross Site Request Forgery.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in RT-Theme 18 Extensions plugin for WordPress allows attackers to force privileged users to execute unwanted actions.

Vulnerability

Overview

The RT-Theme 18 | Extensions plugin for WordPress (versions up to and including 2.5) contains a Cross-Site Request Forgery (CSRF) vulnerability. This flaw arises because the plugin does not properly validate or enforce anti-CSRF tokens on sensitive actions, allowing an attacker to craft malicious requests that can be executed by an authenticated administrator without their knowledge [1].

Exploitation

Requirements

Exploitation requires user interaction: a privileged user (such as an administrator) must be tricked into clicking a malicious link, visiting a crafted page, or submitting a specially designed form while logged into the WordPress admin panel. No direct authentication is needed for the attacker, but the victim must have an active session with sufficient privileges to perform the targeted actions [1].

Impact

If successfully exploited, an attacker can force the victim to perform unintended actions under their current authentication, such as modifying plugin settings, creating new admin users, or changing site configurations. This can lead to partial compromise of the WordPress site, depending on the capabilities of the targeted actions [1].

Mitigation

The vendor has not released a patched version as of the publication date. Users are strongly advised to update the plugin immediately if a fix becomes available. If updating is not possible, contacting the hosting provider or a web developer for assistance is recommended. This vulnerability is noted as being used in mass-exploit campaigns, so prompt action is critical [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.