Unauthenticated SQL Injection in rtMedia for WordPress by rtCamp
CVE-2026-66592
9.3CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2026
What is CVE-2026-66592?
An unauthenticated SQL Injection vulnerability exists in rtMedia for WordPress, affecting versions up to 4.7.11. This flaw allows attackers to execute arbitrary SQL queries through specially crafted input, which can lead to unauthorized data access and manipulation. It impacts installations utilizing BuddyPress and bbPress, making it critical for users of the plugin to upgrade to the latest version to mitigate potential exploitation.
Affected Version(s)
rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11