CVE-2026-57743 | stmcan RT-Theme 18 Plugin up to 2.5 on WordPress Include/Require include filename file inclusion
A vulnerability marked as critical has been reported in stmcan RT-Theme 18 Plugin up to 2.5 on WordPress. This impacts the function include of the component Include/Require. The manipulation of the argument filename leads to file inclusion.
This vulnerability is traded as CVE-2026-57743. It is possible to initiate the attack remotely. There is no exploit available.