CVE-2026-105892: WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.13 - Arbitrary File Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc. rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Path Traversal.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.7.13.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rtMedia for WordPress, BuddyPress and bbPressto a version that resolves this vulnerability.Fixed in 4.7.14
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates it can be exploited over the network with low attack complexity. No authentication or user interaction is required.
Which installations should be considered affected?
rtMedia for WordPress, BuddyPress and bbPress is affected through version 4.7.13. The provided data does not identify a fixed version or any unaffected configuration.
What is the potential security impact?
The issue is rated critical with high impacts to confidentiality, integrity, and availability. It can enable arbitrary file deletion through path traversal.