CVE-2026-59549
This vulnerability is an unauthenticated SQL injection in the rtMedia plugin for WordPress, BuddyPress, and bbPress versions up to 4.7.10. It allows attackers to read or modify database contents without needing to log in. The flaw can be exploited over the network and can lead to loss of confidentiality.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
rtMedia plugin for WordPress, BuddyPress and bbPress versions 4.7.10 and earlier. Typical users are site administrators and developers who use these plugins.
Real-world impact
An attacker could read sensitive data from the database, such as user credentials or private content, and could also modify or delete data, potentially disrupting site functionality.
Why this severity
The CVSS score of 9.3 reflects that the flaw can be exploited remotely without authentication, changes the scope of the system, and gives attackers full confidentiality access to the database. The low attack complexity and lack of required privileges make it highly dangerous.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources