VYPR

rtMedia for WordPress, BuddyPress and bbPress

by WordPress

Source repositories

CVEs (5)

  • CVE-2023-5931HigDec 26, 2023
    risk 0.57cvss 8.8epss 0.01

    The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server

  • CVE-2024-3293HigApr 23, 2024
    risk 0.50cvss 8.8epss 0.01

    The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtmedia_gallery shortcode in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2023-5939HigDec 26, 2023
    risk 0.47cvss 7.2epss 0.01

    The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users.

  • CVE-2026-16482HigSep 12, 2026
    risk 0.42cvss 7.5epss 0.00

    The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-25325MedFeb 19, 2026
    risk 0.34cvss 5.3epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Retrieve Embedded Sensitive Data.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a…