Executive brief
rtMedia is a popular WordPress plugin used to manage and display media (photos, videos, documents) on BuddyPress and bbPress community sites. An unauthenticated SQL injection vulnerability allows attackers to read, modify, or delete entire databases including user accounts and private data without needing any login credentials. This could lead to complete compromise of affected websites, theft of sensitive customer data, and reputational damage.
Technical details
This is an unauthenticated SQL injection vulnerability in the rtMedia plugin affecting versions up to 4.7.11. The vulnerability allows attackers to inject arbitrary SQL commands without authentication required, exploiting a failure to properly sanitize user input before using it in database queries. An attacker with network access can craft malicious requests to execute arbitrary SQL operations, potentially reading sensitive data from the database, modifying records, or deleting entire tables. The vulnerability has been patched in version 4.7.12 and later. Patchstack has released a mitigation rule to block exploit attempts for users unable to update immediately.
Affected products
- rtMedia rtMedia for WordPress, BuddyPress and bbPress <=4.7.11
Timeline
- 2026-08-20: disclosed
- 2026-08-19: patched: Version 4.7.12 released