Executive brief
rtMedia is a WordPress plugin used to manage media files within community-driven websites. A security flaw allows logged-in users with low-level 'Subscriber' permissions to perform actions they should not be authorized to do. This could lead to unauthorized changes to site content or media settings, potentially disrupting community operations.
Technical details
The rtMedia plugin for WordPress (versions 4.7.9 and below) contains a broken access control vulnerability classified as CWE-862 (Missing Authorization). The flaw exists because the plugin fails to properly validate user permissions or implement sufficient nonce checks on certain functions. An attacker authenticated with Subscriber-level privileges can exploit this over the network to execute actions typically reserved for higher-privileged users, specifically impacting data integrity. The issue is resolved in version 4.7.10.
Affected products
- rtMedia rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9
Timeline
- 2026-03-09: other: Reported by Jakub Herman
- 2026-04-21: advisory: Initial advisory published by Patchstack
- 2026-04-21: patched: Version 4.7.10 released
- 2026-06-15: disclosed: NVD publication date