
CVE-2025-12473 The RTMKit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'themebuilder' parameter in all versions up to, and including, 1.6.8 due to in… https://www.cve.org/CVERecord?id=CVE-2025-12473
Post summary
The RTMKit WordPress plugin is vulnerable to reflected XSS through the 'themebuilder' parameter in all versions up to 1.6.8, as detailed in the CVE record.
