CVE-2026-66592: WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.11 - SQL Injection vulnerability
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress rtMedia for WordPress, BuddyPress and bbPress pluginto a version that resolves this vulnerability.Fixed in 4.7.12
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation. Network-accessible installations running an affected rtMedia version are exposed.
Which versions are affected?
rtMedia for WordPress, BuddyPress and bbPress versions 4.7.11 and earlier are identified as affected. The provided information does not specify a fixed version.
What is the potential impact?
This is a critical SQL injection issue with a CVSS vector of AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L. It may allow remote, low-complexity attacks without privileges or user interaction, with high confidentiality impact and low availability impact.