Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-59549: WordPress rtMedia Plugin SQL Injection Risk

CVE-2026-59549 · published 2 months ago
Summary

The rtMedia plugin for WordPress, BuddyPress, and bbPress is vulnerable to a SQL Injection attack. This means that an attacker could potentially access or manipulate sensitive data in your WordPress database. Update the rtMedia plugin to version 4.7.11 or later to fix this issue.

What to do
  • Update rtcamp rtmedia for wordpress, buddypress and bbpress to version 4.7.11.
Affected software
VendorProductAffected versions
rtcamp rtmedia for wordpress, buddypress and bbpress <= 4.7.10
Fix: upgrade to 4.7.11
Original advisory text
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Severity
9.3 Critical
CVSS 3.1: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published27 Jul 2026
Updated27 Sep 2026
First seen27 Jul 2026
Sources
CVE-2026-59549 · MITRE
Track software like this
Free during beta