File Deletion Vulnerability in rtMedia Plugin for WordPress by rtCamp
CVE-2026-89301
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-89301?
The rtMedia plugin for WordPress, specifically versions up to and including 4.7.13, has a vulnerability that arises from inadequate validation of file paths. This weakness allows unauthenticated users to exploit the system and delete arbitrary files stored on the server. The nonce (rtmedia_upload_nonce) used within the plugin's frontend code is publicly accessible on any page that includes the rtMedia gallery or upload shortcode, enabling attackers to manipulate uploads without requiring authentication, potentially leading to unauthorized file deletion.
Affected Version(s)
rtMedia for WordPress, BuddyPress and bbPress 0 <= 4.7.13