Extension WordPress
Vulnérabilités rtMedia for WordPress, BuddyPress and bbPress
Cette page rassemble les failles publiées pour rtMedia for WordPress, BuddyPress and bbPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de rtMedia for WordPress, BuddyPress and bbPress
14 fiches
rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 – Missing Authorization
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.7.9. This makes it possible for authenticated attackers,…
*-4.7.9
4.7.10
21/04/2026
rtMedia for WordPress, BuddyPress and bbPress <= 4.7.8 – Unauthenticated Information Exposure
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
*-4.7.8
4.7.9
01/02/2026
rtMedia for WordPress, BuddyPress and bbPress 4.7.0 – 4.7.3 – Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it…
4.7.0-4.7.3
4.7.4
12/12/2025
rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 – Authenticated (Subscriber+) SQL Injection
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the order_by parameter in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and…
*-4.6.18
4.6.19
29/04/2024
rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 – Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtmedia_gallery shortcode in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and…
*-4.6.18
4.6.19
22/04/2024
rtMedia for WordPress, BuddyPress and bbPress <= 4.6.15 – Authenticated (Subscriber+) Arbitrary File Upload
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rtmedia_api_process_rtmedia_upload_media_request() function in all versions up to, and including, 4.6.15. This makes it possible…
*-4.6.15
4.6.16
29/11/2023
rtMedia for WordPress, BuddyPress and bbPress WordPress <= 4.6.15 – Authenticated (Admin+) Arbitrary File Upload
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Import rtMedia Settings functionality in all versions up to, and including, 4.6.15. This makes…
*-4.6.15
4.6.16
29/11/2023
rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 – Missing Authorization via export_settings
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the export_settings function in versions up to, and including, 4.6.14. This makes it possible for…
*-4.6.14
4.6.15
06/09/2023
rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 – Missing Authorization to Sensitive Information Exposure
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_settings function in versions up to, and including, 4.6.14. This makes it possible…
[*, 4.6.15)
4.6.15
04/09/2023
rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 – Missing Authorization to Settings Update
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtmedia_admin_upload function in versions up to, and including, 4.6.14. This makes it possible…
[*, 4.6.15)
4.6.15
04/09/2023
rtMedia for WordPress, BuddyPress and bbPress <= 4.2 – Arbitary File Upload
The rtMedia for WordPress, BuddyPress and bbPress for WordPress is vulnerable to Direct file access in versions up to, and including, 4.2. This is due to the 'rtUploadAttachment.php' file preventing direct access to the the file. This makes…
[*, 4.2.1)
4.2.1
21/12/2016
rtMedia for WordPress, BuddyPress and bbPress <= 3.10.1 – Cross-Site Scripting
The rtMedia for WordPress, BuddyPress and bbPress Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_title’ parameter in versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it…
[*, 3.10.2)
3.10.2
28/01/2016
rtMedia for WordPress, BuddyPress and bbPress < 3.7.40 – SQL Injection
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘rtmedia_activity_upgrade’ method in versions up to, and including, 3.7.39 due to insufficient escaping on the user supplied parameter and lack…
[*, 3.7.40)
3.7.40
28/04/2015
rtMedia for WordPress, BuddyPress and bbPress <= 3.9.5 – Local File Inclusion
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.5 via the 'template' parameter. This allows unauthenticated attackers to include and execute arbitrary files on…
*-3.9.5
3.10
24/11/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.