Extension WordPress

Vulnérabilités rtMedia for WordPress, BuddyPress and bbPress

Cette page rassemble les failles publiées pour rtMedia for WordPress, BuddyPress and bbPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
3Critiques
14Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de rtMedia for WordPress, BuddyPress and bbPress

14 fiches

CVE-2026-40773 Moyenne · 4,3
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 – Missing Authorization

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.7.9. This makes it possible for authenticated attackers,…

Versions affectées

*-4.7.9

Correctif

4.7.10

Publication

21/04/2026

CVE-2026-25325 Moyenne · 5,3
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.8 – Unauthenticated Information Exposure

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Versions affectées

*-4.7.8

Correctif

4.7.9

Publication

01/02/2026

CVE-2025-9218 Faible · 3,7
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress 4.7.0 – 4.7.3 – Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it…

Versions affectées

4.7.0-4.7.3

Correctif

4.7.4

Publication

12/12/2025

CVE-2026-15287 Moyenne · 6,5
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 – Authenticated (Subscriber+) SQL Injection

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the order_by parameter in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and…

Versions affectées

*-4.6.18

Correctif

4.6.19

Publication

29/04/2024

CVE-2024-3293 Élevée · 8,8
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 – Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtmedia_gallery shortcode in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and…

Versions affectées

*-4.6.18

Correctif

4.6.19

Publication

22/04/2024

CVE-2023-5931 Élevée · 8,8
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.15 – Authenticated (Subscriber+) Arbitrary File Upload

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rtmedia_api_process_rtmedia_upload_media_request() function in all versions up to, and including, 4.6.15. This makes it possible…

Versions affectées

*-4.6.15

Correctif

4.6.16

Publication

29/11/2023

CVE-2023-5939 Élevée · 7,2
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress WordPress <= 4.6.15 – Authenticated (Admin+) Arbitrary File Upload

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Import rtMedia Settings functionality in all versions up to, and including, 4.6.15. This makes…

Versions affectées

*-4.6.15

Correctif

4.6.16

Publication

29/11/2023

CVE-2023-41951 Moyenne · 4,3
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 – Missing Authorization via export_settings

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the export_settings function in versions up to, and including, 4.6.14. This makes it possible for…

Versions affectées

*-4.6.14

Correctif

4.6.15

Publication

06/09/2023

Vulnérabilité Moyenne · 4,3
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 – Missing Authorization to Sensitive Information Exposure

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_settings function in versions up to, and including, 4.6.14. This makes it possible…

Versions affectées

[*, 4.6.15)

Correctif

4.6.15

Publication

04/09/2023

Vulnérabilité Moyenne · 4,3
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 – Missing Authorization to Settings Update

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtmedia_admin_upload function in versions up to, and including, 4.6.14. This makes it possible…

Versions affectées

[*, 4.6.15)

Correctif

4.6.15

Publication

04/09/2023

Vulnérabilité Moyenne · 6,1
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress <= 3.10.1 – Cross-Site Scripting

The rtMedia for WordPress, BuddyPress and bbPress Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_title’ parameter in versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

[*, 3.10.2)

Correctif

3.10.2

Publication

28/01/2016

Vulnérabilité Critique · 9,8
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress < 3.7.40 – SQL Injection

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘rtmedia_activity_upgrade’ method in versions up to, and including, 3.7.39 due to insufficient escaping on the user supplied parameter and lack…

Versions affectées

[*, 3.7.40)

Correctif

3.7.40

Publication

28/04/2015

Vulnérabilité Critique · 9,8
rtMedia for WordPress, BuddyPress and bbPress

rtMedia for WordPress, BuddyPress and bbPress <= 3.9.5 – Local File Inclusion

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.5 via the 'template' parameter. This allows unauthenticated attackers to include and execute arbitrary files on…

Versions affectées

*-3.9.5

Correctif

3.10

Publication

24/11/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités