Junglewise Threat Intelligence

CVE-2026-66592: rtMedia for WordPress, BuddyPress and bbPress SQL injection

CVE-2026-66592 · Severity: critical · CVSS 9.3 · Published 2026-08-20

Executive brief

rtMedia is a popular WordPress plugin used to manage and display media (photos, videos, documents) on BuddyPress and bbPress community sites. An unauthenticated SQL injection vulnerability allows attackers to read, modify, or delete entire databases including user accounts and private data without needing any login credentials. This could lead to complete compromise of affected websites, theft of sensitive customer data, and reputational damage.

Technical details

This is an unauthenticated SQL injection vulnerability in the rtMedia plugin affecting versions up to 4.7.11. The vulnerability allows attackers to inject arbitrary SQL commands without authentication required, exploiting a failure to properly sanitize user input before using it in database queries. An attacker with network access can craft malicious requests to execute arbitrary SQL operations, potentially reading sensitive data from the database, modifying records, or deleting entire tables. The vulnerability has been patched in version 4.7.12 and later. Patchstack has released a mitigation rule to block exploit attempts for users unable to update immediately.

Affected products

  • rtMedia rtMedia for WordPress, BuddyPress and bbPress <=4.7.11

Timeline

  • 2026-08-20: disclosed
  • 2026-08-19: patched: Version 4.7.12 released

References

Related threats