Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-66592: rtMedia plugin up to 4.7.11 lets attackers alter site data

CVE-2026-66592 · published 1 month ago
Summary

Websites that run WordPress and use the rtMedia plugin version 4.7.11 or earlier are at risk. An attacker on the internet could send a crafted request that changes the site's database without needing a login, potentially exposing or destroying information. Update the plugin to the newest release or remove it if you don't need it, and check the site for any unexpected changes.

What to do
  • Update rtcamp rtmedia for wordpress, buddypress and bbpress to version 4.7.12.
Affected software
VendorProductAffected versions
rtcamp rtmedia for wordpress, buddypress and bbpress <= 4.7.11
Fix: upgrade to 4.7.12
Original advisory text
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Severity
9.3 Critical
CVSS 3.1: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published20 Aug 2026
Updated26 Sep 2026
First seen20 Aug 2026
Sources
CVE-2026-66592 · MITRE
Track software like this
Free during beta