CVE-2023-5931: rtMedia for WordPress, BuddyPress and bbPress < 4.6.16 - Subscriber+ RCE
The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5931?
CVE-2023-5931 is considered a critical vulnerability due to its potential to allow unauthorized file uploads by low-privilege users.
How do I fix CVE-2023-5931?
Upgrading the rtMedia plugin for WordPress to version 4.6.16 or later will resolve the vulnerability.
What are the potential effects of CVE-2023-5931?
If exploited, CVE-2023-5931 allows attackers to upload arbitrary files, potentially leading to server compromise.
Who is affected by CVE-2023-5931?
Any WordPress site using rtMedia plugin versions before 4.6.16 is vulnerable to CVE-2023-5931.
What is the nature of the attack enabled by CVE-2023-5931?
CVE-2023-5931 enables low-privileged users to upload harmful files, such as malicious PHP scripts, to the server.