Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-59549: WordPress rtMedia Plugin SQL Injection Risk

CVE-2026-59549 CVE-2026-59549
Summary

The rtMedia plugin for WordPress, BuddyPress, and bbPress is vulnerable to a SQL Injection attack. This means that an attacker could potentially access or manipulate sensitive data in your WordPress database. Update the rtMedia plugin to version 4.7.11 or later to fix this issue.

What to do
  • Update rtcamp rtmedia for wordpress, buddypress and bbpress to version 4.7.11.
Affected software
VendorProductAffected versions
rtcamp rtmedia for wordpress, buddypress and bbpress <= 4.7.10
Fix: upgrade to 4.7.11
Original title
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Original description
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
nvd CVSS3.1 9.3
Vulnerability type
CWE-89 SQL Injection
Published: 27 Jul 2026 · Updated: 29 Jul 2026 · First seen: 27 Jul 2026