Junglewise Threat Intelligence

CVE-2026-59549: rtCamp rtMedia unauthenticated SQL injection

CVE-2026-59549 · Severity: critical · CVSS 9.3 · Published 2026-07-27

Technologies: rtCamp rtMedia. Vendors: rtCamp.

Executive brief

rtMedia is a popular WordPress plugin used to add media galleries to social networking sites powered by BuddyPress and bbPress. A critical security flaw allows unauthorized attackers to interact directly with the website's database without needing a password. This could lead to the theft of sensitive user information, exposure of private site data, or disruption of website operations.

Technical details

A SQL injection vulnerability exists in the rtMedia plugin (buddypress-media) for WordPress due to improper neutralization of special elements in SQL commands (CWE-89). The flaw allows an unauthenticated remote attacker to execute arbitrary SQL queries against the backend database. This is achieved via a network-based attack vector with low complexity and no user interaction required. Successful exploitation could lead to unauthorized data extraction or limited impact on service availability. The vulnerability is addressed in version 4.7.11.

Affected products

  • rtCamp rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10

Timeline

  • 2026-07-10: disclosed: Reported by Zainul Anwar Adi Putra
  • 2026-07-23: advisory: Patchstack published advisory
  • 2026-07-27: advisory: NVD published CVE record
  • patched: Fixed in version 4.7.11

References

Related threats