CVE-2026-40773: WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.9 - Broken Access Control vulnerability
Published Jun 15, 2026
·Updated
Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions.
Affected Software
1 affected component
rtMedia rtMedia for WordPress, BuddyPress and bbPress<=4.7.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rtMedia for WordPress, BuddyPress and bbPressto a version that resolves this vulnerability.Fixed in 4.7.10
Event History
Jun 15, 2026
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Subscriber-level access to an affected rtMedia installation. The vulnerability is remotely exploitable and does not require user interaction.
2
What is the potential impact?
The issue can affect integrity, with a CVSS vector indicating high impact on integrity and no stated impact on confidentiality or availability.
3
Which versions are affected?
rtMedia for WordPress, BuddyPress and bbPress versions 4.7.9 and earlier are affected.