SQL Injection Vulnerability in rtMedia Plugin for WordPress
CVE-2026-16482
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 September 2026
What is CVE-2026-16482?
The rtMedia plugin for WordPress, including its integration with BuddyPress and bbPress, is affected by a serious SQL injection vulnerability. This issue arises from insufficient escaping of the 'compare' parameter in the SQL queries, allowing unauthenticated attackers to inject malicious SQL code. When an rtMedia shortcode is present on a public page, such as [rtmedia_gallery], attackers can exploit this vulnerability without authentication. The plugin's handling of the $_REQUEST array permits inadequate validation, enabling the 'compare' parameter to bypass security measures and access the vulnerable database queries. This vulnerability poses significant risks, including the potential exposure of sensitive information stored within the database.
Affected Version(s)
rtMedia for WordPress, BuddyPress and bbPress 0 <= 4.7.11