plugin

Buddypress Media Vulnerabilities

35 known security issues reported for the Buddypress Media WordPress plugin. Most recent disclosed Aug 19, 2026.

3 critical 5 high 8 medium 1 low

Running Buddypress Media on your site? Check whether your installed version is affected.

Scan your site free

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 - Unauthenticated SQL Injection

high

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.7.11. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated...

CVSS:
7.5
Affected:
up to 4.7.11
Fixed in:
4.7.12
Disclosed:
Aug 19, 2026

CVE-2026-66592 on NVD →

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 - Unauthenticated SQL Injection

high

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.7.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to...

CVSS:
7.5
Affected:
up to 4.7.10
Fixed in:
4.7.11
Disclosed:
Jul 23, 2026

CVE-2026-59549 on NVD →

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 - Authenticated (Subscriber+) SQL Injection

medium

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.7.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wit...

CVSS:
6.5
Affected:
up to 4.7.10
Fixed in:
4.7.11
Disclosed:
Jul 23, 2026

CVE-2026-59551 on NVD →

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 - Missing Authorization

medium

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.7.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized acti...

CVSS:
4.3
Affected:
up to 4.7.9
Fixed in:
4.7.10
Disclosed:
Apr 21, 2026

CVE-2026-40773 on NVD →

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] <= 4.7.8 (unfixed)

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Retrieve Embedded Sensitive Data.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through <= 4.7.8.

Affected:
up to 4.7.8
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25325 on NVD →

rtMedia for WordPress, BuddyPress and bbPress <= 4.7.8 - Unauthenticated Information Exposure

medium

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.7.8. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 4.7.8
Fixed in:
4.7.9
Disclosed:
Feb 1, 2026

CVE-2026-25325 on NVD →

rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function

low

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it possible for unauthenticated attackers to retrieve media it...

CVSS:
3.7
Affected:
4.7.0 – 4.7.3
Fixed in:
4.7.4
Disclosed:
Dec 12, 2025

CVE-2025-9218 on NVD →

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.15

unknown

[en] Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.6.14.

Affected:
up to 4.6.15
Fixed in:
4.6.15
Disclosed:
Dec 13, 2024

CVE-2023-41951 on NVD →

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Subscriber+) SQL Injection

medium

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the order_by parameter in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i...

CVSS:
6.5
Affected:
up to 4.6.18
Fixed in:
4.6.19
Disclosed:
Apr 29, 2024

CVE-2026-15287 on NVD →

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.19

unknown

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the order_by parameter in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i...

Affected:
up to 4.6.19
Fixed in:
4.6.19
Disclosed:
Apr 29, 2024

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.19

unknown

<p>WordPress rtMedia for WordPress, BuddyPress and bbPress Plugin <= 4.6.18 is vulnerable to SQL Injection</p><p>Software: rtMedia for WordPress, BuddyPress and bbPress</p><p>Link: https://wordpress.org/plugins/buddypress-media/#developers</p><p>Affected Version <= 4.6.18</p>

Affected:
up to 4.6.19
Fixed in:
4.6.19
Disclosed:
Apr 29, 2024

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.19

unknown

[en] The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtmedia_gallery shortcode in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

Affected:
up to 4.6.19
Fixed in:
4.6.19
Disclosed:
Apr 23, 2024

CVE-2024-3293 on NVD →

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode

high

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtmedia_gallery shortcode in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...

CVSS:
8.8
Affected:
up to 4.6.18
Fixed in:
4.6.19
Disclosed:
Apr 22, 2024

CVE-2024-3293 on NVD →

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.16

unknown

[en] The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users.

Affected:
up to 4.6.16
Fixed in:
4.6.16
Disclosed:
Dec 26, 2023

CVE-2023-5939 on NVD →

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.16

unknown

[en] The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server

Affected:
up to 4.6.16
Fixed in:
4.6.16
Disclosed:
Dec 26, 2023

CVE-2023-5931 on NVD →

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.15 - Authenticated (Subscriber+) Arbitrary File Upload

high

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rtmedia_api_process_rtmedia_upload_media_request() function in all versions up to, and including, 4.6.15. This makes it possible for authenticated attackers, with sub...

CVSS:
8.8
Affected:
up to 4.6.15
Fixed in:
4.6.16
Disclosed:
Nov 29, 2023

CVE-2023-5931 on NVD →

rtMedia for WordPress, BuddyPress and bbPress WordPress <= 4.6.15 - Authenticated (Admin+) Arbitrary File Upload

high

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Import rtMedia Settings functionality in all versions up to, and including, 4.6.15. This makes it possible for authenticated attackers, with administrator-level acces...

CVSS:
7.2
Affected:
up to 4.6.15
Fixed in:
4.6.16
Disclosed:
Nov 29, 2023

CVE-2023-5939 on NVD →

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization via export_settings

medium

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the export_settings function in versions up to, and including, 4.6.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to expo...

CVSS:
4.3
Affected:
up to 4.6.14
Fixed in:
4.6.15
Disclosed:
Sep 6, 2023

CVE-2023-41951 on NVD →

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization to Settings Update

medium

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtmedia_admin_upload function in versions up to, and including, 4.6.14. This makes it possible for authenticated attackers, with subscriber-level and above p...

CVSS:
4.3
Affected:
up to 4.6.15
Fixed in:
4.6.15
Disclosed:
Sep 4, 2023

rtMedia for WordPress, BuddyPress and bbPress <= 4.6.14 - Missing Authorization to Sensitive Information Exposure

medium

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_settings function in versions up to, and including, 4.6.14. This makes it possible for authenticated attackers, with subscriber-level and above permissions,...

CVSS:
4.3
Affected:
up to 4.6.15
Fixed in:
4.6.15
Disclosed:
Sep 4, 2023

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.15

unknown

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtmedia_admin_upload function in versions up to, and including, 4.6.14. This makes it possible for authenticated attackers, with subscriber-level and above p...

Affected:
up to 4.6.15
Fixed in:
4.6.15
Disclosed:
Sep 4, 2023

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.15

unknown

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_settings function in versions up to, and including, 4.6.14. This makes it possible for authenticated attackers, with subscriber-level and above permissions,...

Affected:
up to 4.6.15
Fixed in:
4.6.15
Disclosed:
Sep 4, 2023

rtMedia for WordPress, BuddyPress and bbPress <= 4.2 - Arbitary File Upload

critical

The rtMedia for WordPress, BuddyPress and bbPress for WordPress is vulnerable to Direct file access in versions up to, and including, 4.2. This is due to the 'rtUploadAttachment.php' file preventing direct access to the the file. This makes it possible for unauthenticated attackers to access the file directly which tri...

CVSS:
9.8
Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
Dec 21, 2016

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.2.1

unknown

The rtMedia for WordPress, BuddyPress and bbPress for WordPress is vulnerable to Direct file access in versions up to, and including, 4.2. This is due to the 'rtUploadAttachment.php' file preventing direct access to the the file. This makes it possible for unauthenticated attackers to access the file directly which tri...

Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
Dec 21, 2016

rtMedia for WordPress, BuddyPress and bbPress <= 3.10.1 - Cross-Site Scripting

medium

The rtMedia for WordPress, BuddyPress and bbPress Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_title’ parameter in versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit...

CVSS:
6.1
Affected:
up to 3.10.2
Fixed in:
3.10.2
Disclosed:
Jan 28, 2016

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 3.10.2

unknown

The rtMedia for WordPress, BuddyPress and bbPress Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_title’ parameter in versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit...

Affected:
up to 3.10.2
Fixed in:
3.10.2
Disclosed:
Jan 28, 2016

rtMedia for WordPress, BuddyPress and bbPress < 3.7.40 - SQL Injection

critical

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘rtmedia_activity_upgrade’ method in versions up to, and including, 3.7.39 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

CVSS:
9.8
Affected:
up to 3.7.40
Fixed in:
3.7.40
Disclosed:
Apr 28, 2015

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 3.7.40

unknown

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘rtmedia_activity_upgrade’ method in versions up to, and including, 3.7.39 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

Affected:
up to 3.7.40
Fixed in:
3.7.40
Disclosed:
Apr 28, 2015

rtMedia for WordPress, BuddyPress and bbPress <= 3.9.5 - Local File Inclusion

critical

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.5 via the 'template' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those f...

CVSS:
9.8
Affected:
up to 3.9.5
Fixed in:
3.10
Disclosed:
Nov 24, 2014

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 3.7.19

unknown

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.5 via the 'template' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those f...

Affected:
up to 3.7.19
Fixed in:
3.7.19
Disclosed:
Nov 24, 2014

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.15

unknown

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtmedia_admin_upload function in versions up to, and including, 4.6.14. This makes it possible for authenticated attackers, with subscriber-level and above p...

Affected:
up to 4.6.15
Fixed in:
4.6.15

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.6.15

unknown

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_settings function in versions up to, and including, 4.6.14. This makes it possible for authenticated attackers, with subscriber-level and above permissions,...

Affected:
up to 4.6.15
Fixed in:
4.6.15

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 3.7.40

unknown
Affected:
up to 3.7.40
Fixed in:
3.7.40

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 3.10.2

unknown
Affected:
up to 3.10.2
Fixed in:
3.10.2

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.2.1

unknown

Changelog for 4.2.1 mentions &quot;Security issues pointed out by James Golovich&quot;, but could not find any reference on the author&#039;s blog

Affected:
up to 4.2.1
Fixed in:
4.2.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database