Unauthenticated SQL Injection in rtMedia for WordPress by rtCamp
CVE-2026-66592

9.3CRITICAL

What is CVE-2026-66592?

An unauthenticated SQL Injection vulnerability exists in rtMedia for WordPress, affecting versions up to 4.7.11. This flaw allows attackers to execute arbitrary SQL queries through specially crafted input, which can lead to unauthorized data access and manipulation. It impacts installations utilizing BuddyPress and bbPress, making it critical for users of the plugin to upgrade to the latest version to mitigate potential exploitation.

Affected Version(s)

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aydan Arabadzha | Patchstack Bug Bounty Program
.