SQL Injection Vulnerability in rtMedia Plugin for WordPress
CVE-2026-16482

7.5HIGH

What is CVE-2026-16482?

The rtMedia plugin for WordPress, including its integration with BuddyPress and bbPress, is affected by a serious SQL injection vulnerability. This issue arises from insufficient escaping of the 'compare' parameter in the SQL queries, allowing unauthenticated attackers to inject malicious SQL code. When an rtMedia shortcode is present on a public page, such as [rtmedia_gallery], attackers can exploit this vulnerability without authentication. The plugin's handling of the $_REQUEST array permits inadequate validation, enabling the 'compare' parameter to bypass security measures and access the vulnerable database queries. This vulnerability poses significant risks, including the potential exposure of sensitive information stored within the database.

Affected Version(s)

rtMedia for WordPress, BuddyPress and bbPress 0 <= 4.7.11

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.