Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress
CVE-2026-59549

9.3CRITICAL

What is CVE-2026-59549?

An unauthenticated SQL Injection vulnerability in rtMedia for WordPress allows attackers to manipulate database queries. This affects versions 4.7.10 and earlier, impacting sites using this plugin alongside BuddyPress and bbPress. Successful exploitation can lead to unauthorized access and data leakage, highlighting the importance of timely updates and security measures for users.

Affected Version(s)

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zainul Anwar Adi Putra | Patchstack Bug Bounty Program
.