Junglewise Threat Intelligence

CVE-2026-40773: rtMedia for WordPress broken access control

CVE-2026-40773 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: rtCamp rtMedia. Vendors: rtCamp.

Executive brief

rtMedia is a WordPress plugin used to manage media files within community-driven websites. A security flaw allows logged-in users with low-level 'Subscriber' permissions to perform actions they should not be authorized to do. This could lead to unauthorized changes to site content or media settings, potentially disrupting community operations.

Technical details

The rtMedia plugin for WordPress (versions 4.7.9 and below) contains a broken access control vulnerability classified as CWE-862 (Missing Authorization). The flaw exists because the plugin fails to properly validate user permissions or implement sufficient nonce checks on certain functions. An attacker authenticated with Subscriber-level privileges can exploit this over the network to execute actions typically reserved for higher-privileged users, specifically impacting data integrity. The issue is resolved in version 4.7.10.

Affected products

  • rtMedia rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9

Timeline

  • 2026-03-09: other: Reported by Jakub Herman
  • 2026-04-21: advisory: Initial advisory published by Patchstack
  • 2026-04-21: patched: Version 4.7.10 released
  • 2026-06-15: disclosed: NVD publication date

References

Related threats