Rstheme develops WordPress theme and plugin products, with its vulnerability footprint concentrated around the Ultimate Coming Soon & Maintenance plugin. The observed weakness classes—cross-site request forgery and missing authorization—reflect common plugin-layer implementation gaps in web application access control and state-changing request validation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rstheme over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9706MEDIUM The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ucsm_activate_lite_template_ | Dec 6, 2024 | 5.3 | 17 | NO | NO |
CVE-2025-24546MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allows Cross Site Request Forgery.This issue affects Ultimate Com | Jan 24, 2025 | 5.4 | 16 | NO | NO |
CVE-2025-24543MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allows Cross Site Request Forgery.This issue affects Ultimate Com | Jan 24, 2025 | 4.3 | 15 | NO | NO |
CVE-2024-9705MEDIUM The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ucsm_update_template_name_l | Dec 6, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rstheme.
Media articles that mention a CVE ID that affects a product developed by Rstheme — matched by CVE ID, not by vendor name.