Impact
The rtMedia for WordPress, BuddyPress and bbPress plugin is vulnerable to a time‑based SQL injection through the order_by parameter in all versions up to and including 4.6.18, due to insufficient escaping and the absence of prepared statements. An authenticated user with Subscriber privileges or higher can append arbitrary SQL to the existing query, allowing extraction of sensitive database information. The flaw affects confidentiality only and does not provide remote code execution or privilege escalation.
Affected Systems
rtcamp:rtMedia plugin for WordPress, BuddyPress and bbPress versions 4.6.18 and earlier on WordPress sites where users are able to assume at least a Subscriber role and supply the order_by parameter during plugin operations.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating moderate severity. The EPSS score is below 1 %, showing a very low likelihood of exploitation at present. It is not listed in CISA’s KEV catalog. Because exploitation requires an authenticated account with Subscriber or greater privilege, the attack vector is limited to legitimate users who can influence the order_by parameter. Attackers can perform time‑based SQL injection to retrieve confidential data from the database, but the overall risk remains moderate due to the authentication requirement and low exploitation probability.
OpenCVE Enrichment